[Git][security-tracker-team/security-tracker][master] Add CVE-2020-37014/tryton-sao

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jan 30 21:14:38 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c5daf4bd by Salvatore Bonaccorso at 2026-01-30T22:14:17+01:00
Add CVE-2020-37014/tryton-sao

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -99,7 +99,11 @@ CVE-2020-37022 (OpenZ ERP 3.6.60 contains a persistent cross-site scripting vuln
 CVE-2020-37019 (Orchard Core RC1 contains a persistent cross-site scripting vulnerabil ...)
 	NOT-FOR-US: Orchard
 CVE-2020-37014 (Tryton 5.4 contains a persistent cross-site scripting vulnerability in ...)
-	TODO: check
+	- tryton-sao 5.0.26-1
+	NOTE: https://www.exploit-db.com/exploits/48466
+	NOTE: https://www.vulnerability-lab.com/get_content.php?id=2233
+	NOTE: ttps://discuss.tryton.org/t/security-release-for-issue9351/2772
+	NOTE: https://foss.heptapod.net/tryton/tryton/-/issues/9351
 CVE-2020-37003 (Sellacious eCommerce 4.6 contains a persistent cross-site scripting vu ...)
 	NOT-FOR-US: Sellacious eCommerce
 CVE-2020-36998 (Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-sit ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5daf4bdbd123eb698fe36f13eb4fff3ee4a974e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5daf4bdbd123eb698fe36f13eb4fff3ee4a974e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260130/4e6c16d0/attachment.htm>


More information about the debian-security-tracker-commits mailing list