Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 6.0.69
affected
7.0.0 (semver) before 7.0.40
affected
7.1.0 (semver) before 7.4.21
affected
7.5.0 (semver) before 7.6.11
affected
Description
Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 6.0.69
7.0.0 (semver) before 7.0.40
7.1.0 (semver) before 7.4.21
7.5.0 (semver) before 7.6.11
References
discuss.tryton.org/t/security-release-for-issue-14363/8951
foss.heptapod.net/tryton/tryton/-/issues/14363