Junglewise Threat Intelligence

CVE-2025-66421: Tryton sao XSS in completion values

CVE-2025-66421 · Severity: low · CVSS 3.1 · Published 2025-11-30

Executive brief

Tryton sao is the web interface for the Tryton business management platform. An attacker with low-privilege access can inject malicious JavaScript through record names in autocomplete fields, which executes in the context of logged-in users' browsers and can steal sensitive session data or modify records without authorization.

Technical details

Tryton sao fails to escape HTML/JavaScript in autocomplete completion values, allowing stored XSS (CWE-79). The vulnerability exists in the completion field rendering, where record names—which are often user-editable—are injected directly into the DOM without sanitization. An attacker with database write access can craft a record name containing malicious JavaScript; when another user interacts with that completion field, the payload executes in their browser session context, granting access to session tokens and data. The vulnerability affects versions before 7.6.11, 7.4.21, 7.0.40, and 6.0.69. Authentication is required to create malicious records, but user interaction (typing to trigger completion) is needed to trigger execution. Patches are available in the fixed versions.

Affected products

  • Tryton sao before 7.6.11, 7.4.21, 7.0.40, and 6.0.69

Timeline

  • 2025-11-30: disclosed: Published as GHSA-6qj9-2g9m-29x9
  • 2025-11-30: patched: Fixed in versions 7.6.11, 7.4.21, 7.0.40, and 6.0.69

References

Related threats