Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p3p5-xrmv-4j6x | trytond does not enforce access rights for the route of the HTML editor. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 01 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 30 Nov 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. | |
| First Time appeared |
Tryton
Tryton trytond |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tryton
Tryton trytond |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-01T14:10:34.912Z
Reserved: 2025-11-30T00:00:00.000Z
Link: CVE-2025-66423
Updated: 2025-12-01T13:34:22.794Z
Status : Analyzed
Published: 2025-11-30T03:15:48.163
Modified: 2025-12-04T17:10:35.000
Link: CVE-2025-66423
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA