lizparadox_ has discovered that the report name can be used to execute commands on the server.ImpactCVSS v3.0 Base Score: 6.8Attack Vector: NetworkAttack Complexity: LowPrivileges Required: HighUser Interaction: RequiredScope: UnchangedConfidentiality: HighIntegrity: HighAvailability: HighWorkaroundThere is no workaround.ResolutionAll affected users should upgrade trytond to the latest version.Affected versions per series:trytond:8.0: = 7.8.17Referencehttps://bugs.tryton.org/15035Concerns?Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked. 1 post - 1 participant Read full topic