Search CVE reports
1 – 10 of 30 results
CVE-2024-36259
Medium priorityImproper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | — | — |
CVE-2024-12368
Medium priorityImproper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | — | — |
CVE-2021-45111
Low priorityImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-45071
Medium priorityCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-44775
Medium priorityCross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-44547
Medium priorityA sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-44476
Medium priorityA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-44465
Medium priorityImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the...
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-44460
Medium priorityImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via...
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |
CVE-2021-26947
Medium priorityCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.
1 affected package
odoo
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
odoo | Needs evaluation | Needs evaluation | Not in release | Not in release | Ignored |