CVE-2016-1242 is a medium-severity vulnerability affecting multiple versions of the Tryton application (before 3.2.17, 3.4.14, 3.6.12, 3.8.8, and 4.0.4). This flaw allows remote authenticated users with specific permissions to read arbitrary files on the system through the 'file_open' function, primarily via the 'name' parameter. The vulnerability has a CVSSv3 score of 4.4, indicating a medium severity. It requires high privileges and high attack complexity, but successful exploitation could lead to high confidentiality impact by allowing unauthorized access to sensitive files. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. Its EPSS score is very low, suggesting a minimal likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:a:tryton:tryton:4.0.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:a:tryton:tryton:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:a:tryton:tryton:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:a:tryton:tryton:4.0.3:*:*:*:*:*:*:* | ||
<= 3.2.16CPE matchmatch criteria | cpe:2.3:a:tryton:tryton:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.