# Security Release for issue9405

**URL:** https://discuss.tryton.org/t/security-release-for-issue9405/2948
**Category:** News
**Tags:** security
**Created:** [June 29, 2020, 4:30pm UTC](https://discuss.tryton.org/t/security-release-for-issue9405/2948 "2020-06-29T16:30:01Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [June 29, 2020, 4:30pm UTC](https://discuss.tryton.org/t/security-release-for-issue9405/2948/1 "2020-06-29T16:30:01Z")

</div>

## Synopsis

A vulnerability in [sao](https://www.npmjs.com/package/tryton-sao) has been found by [Coopengo](https://www.coopengo.com/) and solved by [Nicolas Évrard](https://bugs.tryton.org/user12).

With [issue 9405](https://bugs.tryton.org/issue9405), the web client does not escape the HTML tags from user data in `richtext` widgets. This allows [cross-site scripting](https://en.wikipedia.org/wiki/Cross-site_scripting) attacks which can result in session hijacking, persistent phishing attacks, and persistent external redirects to a malicious source.

## Impact

[CVSS v3.0 Base Score: 4.6](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Confidentiality: Low
- Integrity: Low
- Availability: None

## Workaround

There is no existing workaround.

# Resolution

All affected users should upgrade `sao` to the latest version.  
Affected versions per series:

- 5.6: \<= 5.6.3
- 5.4: \<= 5.4.9
- 5.2: \<= 5.2.17
- 5.0: \<=5.0.25

Non affected versions per series:

- 5.6: \>= 5.6.4
- 5.4: \>= 5.4.10
- 5.2: \>= 5.2.18
- 5.0: \>= 5.0.26

## Reference

- [issue9405](https://bugs.tryton.org/issue9405)

## Concern?

Any security concerns should be reported on the bug-tracker at  
[https://bugs.tryton.org/](https://bugs.tryton.org/) with the type `security` .

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [July 29, 2020, 4:30pm UTC](https://discuss.tryton.org/t/security-release-for-issue9405/2948/2 "2020-07-29T16:30:10Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
