Critical severity9.8NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-40954
CVE-2023-40954
Description
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:gmarczynski:dynamic_progress_bar:*:*:*:*:*:odoo:*:*Range: >=11.0,<=11.0.2
- Grzegorz Marczynski/Dynamic Progress Bardescription
- Range: 11.0-11.0.2, 12.0-12.0.2, 13.0-13.0.2, 14.0-14.0.2.1, 15.0-15.0.2, 16.0-16.0.2.1
- Range: 11.0-11.0.2, 12.0-12.0.2, 13.0-13.0.2, 14.0-14.0.2.1, 15.0-15.0.2, 16.0-16.0.2.1
Patches
Vulnerability mechanics
References
2- github.com/gmarczynski/odoo-web-progress/commit/3c867f1cf7447449c81b1aa24ebb1f7ae757489fnvdPatch
- github.com/luvsn/OdZoo/tree/main/exploits/web_progressnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.