Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces. | |
| Title | Tryton 5.4 - Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-30T16:31:58.040Z
Reserved: 2026-01-28T18:18:30.521Z
Link: CVE-2020-37014
Updated: 2026-01-30T16:31:55.052Z
Status : Received
Published: 2026-01-30T17:16:11.150
Modified: 2026-01-30T17:16:11.150
Link: CVE-2020-37014
No data.
OpenCVE Enrichment
No data.