← Back

CVE-2025-66423

nvd nist
Published: Nov 30, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.2
Source: MITRE (Secondary)

Description

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Affected (4)

Products: Tryton: Trytond
1 product
Trytond
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Tryton
From 6.0.0 to 6.0.70
From 7.0.0 to 7.0.40
From 7.4.0 to 7.4.21
From 7.6.0 to 7.6.11

References (2)

Source: cve@mitre.org
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.