Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2018-14886
Disclosure Date: June 28, 2019 (last updated November 27, 2024)
The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.
0
Attacker Value
Unknown
CVE-2017-5871
Disclosure Date: May 22, 2019 (last updated November 27, 2024)
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
0
Attacker Value
Unknown
CVE-2017-10804
Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
0
Attacker Value
Unknown
CVE-2017-10805
Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.
0
Attacker Value
Unknown
CVE-2017-10803
Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
0
Attacker Value
Unknown
CVE-2017-9416
Disclosure Date: June 04, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
0