Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66423

Опубликовано: 30 нояб. 2025
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*
Версия от 6.0.0 (включая) до 6.0.70 (исключая)
cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.40 (исключая)
cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*
Версия от 7.4.0 (включая) до 7.4.21 (исключая)
cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*
Версия от 7.6.0 (включая) до 7.6.11 (исключая)

EPSS

Процентиль: 13%
0.00224
Низкий

7.1 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.1
ubuntu
9 месяцев назад

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

CVSS3: 7.1
debian
9 месяцев назад

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for th ...

CVSS3: 7.1
github
9 месяцев назад

trytond does not enforce access rights for the route of the HTML editor.

EPSS

Процентиль: 13%
0.00224
Низкий

7.1 High

CVSS3

Дефекты

CWE-863