Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown

CVE-2018-14867

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
0
Attacker Value
Unknown

CVE-2018-14868

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
0
Attacker Value
Unknown

CVE-2018-14886

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.
0
Attacker Value
Unknown

CVE-2018-14885

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.
0
Attacker Value
Unknown

CVE-2017-5871

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
0
Attacker Value
Unknown

CVE-2018-15631

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.
Attacker Value
Unknown

CVE-2018-15635

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.
0
Attacker Value
Unknown

CVE-2018-15640

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
Attacker Value
Unknown

CVE-2017-10804

Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
0
Attacker Value
Unknown

CVE-2017-10805

Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.
0