CVE-2025-66423

Source
https://cve.org/CVERecord?id=CVE-2025-66423
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66423.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66423
Aliases
Downstream
Published
2025-11-30T03:15:48.163Z
Modified
2026-03-14T12:44:32.997846Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.0.0"
            },
            {
                "fixed": "6.0.70"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.0.0"
            },
            {
                "fixed": "7.0.40"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.4.0"
            },
            {
                "fixed": "7.4.21"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.6.0"
            },
            {
                "fixed": "7.6.11"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "6.0"
            },
            {
                "fixed": "7.6.11"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66423.json"