CVE-2025-66424

MEDIUM6.5EPSS 0.04%

trytond does not enforce access rights for data export

Published: 11/30/2025Modified: 12/2/2025
Also known as:GHSA-2w93-qwpp-vgvjDEBIAN-CVE-2025-66424

Description

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (5)