Vulnerability Description
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tryton | Trytond | >= 6.0.0, < 6.0.70 |
Related Weaknesses (CWE)
References
- https://discuss.tryton.org/t/security-release-for-issue-14354/8950Vendor Advisory
- https://foss.heptapod.net/tryton/tryton/-/issues/14354ExploitIssue Tracking
FAQ
What is CVE-2025-66422?
CVE-2025-66422 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
How severe is CVE-2025-66422?
CVE-2025-66422 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66422?
Check the references section above for vendor advisories and patch information. Affected products include: Tryton Trytond.