Search CVE reports


Toggle filters

1 – 10 of 30 results


CVE-2024-36259

Medium priority
Needs evaluation

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-12368

Medium priority
Needs evaluation

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2021-45111

Low priority
Needs evaluation

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-45071

Medium priority
Needs evaluation

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-44775

Medium priority
Needs evaluation

Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-44547

Medium priority
Needs evaluation

A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-44476

Medium priority
Needs evaluation

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration files.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-44465

Medium priority
Needs evaluation

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the...

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-44460

Medium priority
Needs evaluation

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via...

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages

CVE-2021-26947

Medium priority
Needs evaluation

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.

1 affected package

odoo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
odoo Needs evaluation Needs evaluation Not in release Not in release Ignored
Show less packages