4.3

CVE-2025-66422

Exploit
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TrytonTrytond Version >= 6.0.0 < 6.0.70
TrytonTrytond Version >= 7.0.0 < 7.0.40
TrytonTrytond Version >= 7.4.0 < 7.4.21
TrytonTrytond Version >= 7.6.0 < 7.6.11
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.169
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@mitre.org 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.