Home

Description

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

PUBLISHED Reserved 2025-11-30 | Published 2025-11-30 | Updated 2025-11-30 | Assigner mitre




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

6.0.0 (semver) before 6.0.70
affected

7.0.0 (semver) before 7.0.40
affected

7.1.0 (semver) before 7.4.21
affected

7.5.0 (semver) before 7.6.11
affected

References

discuss.tryton.org/t/security-release-for-issue-14364/8952

foss.heptapod.net/tryton/tryton/-/issues/14364

cve.org (CVE-2025-66423)

nvd.nist.gov (CVE-2025-66423)

Download JSON