{"id":"CVE-2013-4510","aliases":["GHSA-qjmc-wwmw-cq9r","PYSEC-2013-28","PYSEC-2026-1054"],"title":"Tryton Directory Traversal vulnerability","summary":"Tryton Directory Traversal vulnerability","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","vendor":"trytond","product":"trytond","ecosystem":"pip","affected":["trytond"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qjmc-wwmw-cq9r","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4510"},{"url":"https://bugs.tryton.org/issue3446"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/tryton/PYSEC-2013-28.yaml"},{"url":"http://hg.tryton.org/tryton/rev/357d0a4d9cb8"},{"url":"http://www.debian.org/security/2013/dsa-2791"},{"url":"http://www.openwall.com/lists/oss-security/2013/11/04/21"},{"url":"http://www.tryton.org/posts/security-release-for-issue3446.html"}],"tags":["osv","pip"],"epss":0.02173,"epssPercentile":0.81292,"ingestedAt":"2026-07-08T18:25:52.448Z","slug":"CVE-2013-4510","body":"## Overview\n\nDirectory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary files via path separators in the extension of a report.\n\n## Affected packages\n\n- `trytond`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}