« Volver al listado

CVE-2025-66424

Estado: AnalizadaMedia (6.5)—

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-66424",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-66424",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-01T13:33:40.959203Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "Tryton",
          "product": "trytond",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.0",
              "lessThan": "6.0.70",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.0",
              "lessThan": "7.0.40",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.1.0",
              "lessThan": "7.4.21",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.5.0",
              "lessThan": "7.6.11",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:pypi/trytond",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-11-30T03:15:48.360",
  "references": [
    {
      "url": "https://discuss.tryton.org/t/security-release-for-issue-14366/8953",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://foss.heptapod.net/tryton/tryton/-/issues/14366",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70."
    },
    {
      "lang": "es",
      "value": "Tryton trytond 6.0 anterior a 7.6.11 no aplica los derechos de acceso para la exportación de datos. Esto está corregido en 7.6.11, 7.4.21, 7.0.40 y 6.0.70."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E811A8E-7C2B-414F-B929-7AF685F83092",
              "versionEndExcluding": "6.0.70",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "179B2F4A-0AF8-4D72-A371-B0B7A2BD9FBD",
              "versionEndExcluding": "7.0.40",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC73A2FC-9781-4560-9C79-3A6627BF3A73",
              "versionEndExcluding": "7.4.21",
              "versionStartIncluding": "7.4.0"
            },
            {
              "criteria": "cpe:2.3:a:tryton:trytond:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "899860ED-5426-4396-AF24-470DB633F208",
              "versionEndExcluding": "7.6.11",
              "versionStartIncluding": "7.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}