CVE 7.1 HIGH

CVE-2025-66423_CVE-2025-66423

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Basic Information

ID CVE-2025-66423
Source mitre
Published Nov 30, 2025 at 00:00
Modified Nov 30, 2025 at 02:37

Affected Product

Vendor Tryton
Product trytond
Version 6.0.0
Affected Versions Tryton trytond 6.0.0
Tryton trytond 7.0.0
Tryton trytond 7.1.0
Tryton trytond 7.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.