CVE-2025-66423Incorrect Authorization in Trytond

Severity
7.1HIGHNVD
EPSS
0.1%
top 84.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30

Description

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2

Affected Packages4 packages

CVEListV5tryton/trytond7.1.07.4.21+1
NVDtryton/trytond6.0.06.0.70+3
PyPItryton/trytond7.5.07.6.11+3
debiandebian/tryton-server< tryton-server 6.0.29-2+deb12u4 (bookworm)

🔴Vulnerability Details

3
GHSA
trytond does not enforce access rights for the route of the HTML editor.2025-11-30
OSV
trytond does not enforce access rights for the route of the HTML editor.2025-11-30
OSV
CVE-2025-66423: Tryton trytond 62025-11-30

📋Vendor Advisories

1
Debian
CVE-2025-66423: tryton-server - Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of...2025