Tryton News: Security Release for issue 15032

Wait 5 sec.

Jaisurya has discovered that the content of the HTML editor was not escaped.ImpactCVSS v3.0 Base Score: 5.4Attack Vector: NetworkAttack Complexity: LowPrivileges Required: LowUser Interaction: RequiredScope: ChangedConfidentiality: LowIntegrity: LowAvailability: NoneWorkaroundSetup restrictive CSP without unsafe inline script may prevent the attack.ResolutionAll affected users should upgrade trytond to the latest version.Affected versions per series:trytond:8.0: = 7.0.58Referencehttps://bugs.tryton.org/15032Concerns?Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked. 1 post - 1 participant Read full topic