# Security Release for issue9351

**URL:** https://discuss.tryton.org/t/security-release-for-issue9351/2772
**Category:** News
**Tags:** security
**Created:** [May 26, 2020, 8:30am UTC](https://discuss.tryton.org/t/security-release-for-issue9351/2772 "2020-05-26T08:30:00Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [May 26, 2020, 8:30am UTC](https://discuss.tryton.org/t/security-release-for-issue9351/2772/1 "2020-05-26T08:30:00Z")

</div>

## Synopsis

A vulnerability in [sao](https://www.npmjs.com/package/tryton-sao) has been found by Benjamin Kunz Mejri at Vulnerability-Lab. But they publish it without using our responsive disclosure procedure so we had to make this fix in the hurry.

With [issue9351](https://bugs.tryton.org/issue9351), the web client does not escape the HTML tags from user data. This allow [cross-site scripting](https://en.wikipedia.org/wiki/Cross-site_scripting) attack which result in session hijacking, persistent phishing attacks, persistent external redirects to malicious source.

## Impact

[CVSS v3.0 Base Score: 4.6](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Confidentiality: Low
- Integrity: Low
- Availability: None

## Workaround

There is no existing workaround.

# Resolution

All affected users should upgrade `sao` to the latest version.  
Affected versions per series:

- 5.6: \<= 5.6.0
- 5.4: \<= 5.4.6
- 5.2: \<= 5.2.14
- 5.0: \<=5.0.22

Non affected versions per series:

- 5.6: \>= 5.6.1
- 5.4: \>= 5.4.7
- 5.2: \>= 5.2.15
- 5.0: \>= 5.0.23

## Reference

- [issue9351](https://bugs.tryton.org/issue9351)

## Concern?

Any security concerns should be reported on the bug-tracker at  
[https://bugs.tryton.org/](https://bugs.tryton.org/) with the type `security` .
