CVE-2025-66422
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-402
- Published
- 2025-11-30
- Last modified
- 2026-03-13
Affected products
- Tryton trytond
- Tryton trytond
- Tryton trytond
- Tryton trytond
Weakness type
Related vulnerabilities
- CVE-2025-67745 — Myhoard logs backup encryption key in plain text
- CVE-2025-55014 — The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and...
- CVE-2025-49618 — In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId,...
- CVE-2025-52925 — In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken...
- CVE-2025-48383 — Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
- CVE-2025-32360 — In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and...
- CVE-2025-29925 — XWiki allows unregistered users to access private pages information through REST endpoint
- CVE-2025-0502 — Transmission of Private Resources into a New Sphere in Crafter Engine