Search CVE reports


Toggle filters

1 – 10 of 30 results


CVE-2024-36259

Medium priority
Needs evaluation

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-12368

Medium priority
Needs evaluation

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-31129

Medium priority

Some fixes available 4 of 102

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment...

11 affected packages

node-moment, gnucash, mediawiki, ntopng, odoo...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-moment Not affected Fixed Fixed Fixed
gnucash Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ntopng Needs evaluation Needs evaluation Needs evaluation Needs evaluation
odoo Needs evaluation Needs evaluation Not in release Not in release
omnidb Needs evaluation Needs evaluation Needs evaluation Not in release
ruby-momentjs-rails Needs evaluation Needs evaluation Needs evaluation Not in release
sabnzbdplus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
syncthing Needs evaluation Needs evaluation Needs evaluation Needs evaluation
wordpress Needs evaluation Needs evaluation Needs evaluation Needs evaluation
postfixadmin Vulnerable Fixed Not affected Not affected
Show all 11 packages Show less packages

CVE-2021-45111

Low priority
Needs evaluation

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-45071

Medium priority
Needs evaluation

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-44775

Medium priority
Needs evaluation

Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-44547

Medium priority
Needs evaluation

A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-44476

Medium priority
Needs evaluation

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-44465

Medium priority
Needs evaluation

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the...

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages

CVE-2021-44460

Medium priority
Needs evaluation

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via...

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release
Show less packages