CVE-2025-66422
MEDIUMDescription
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tryton | trytond |
| tryton | trytond |
| tryton | trytond |
| tryton | trytond |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-66422? +
How severe is CVE-2025-66422? +
What products are affected by CVE-2025-66422? +
How do I check if I'm vulnerable to CVE-2025-66422? +
Related Vulnerabilities
Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 …
Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget …
Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. …
MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, …
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial …
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.