High severity7.5NVD Advisory· Published Feb 25, 2025· Updated Jun 17, 2026
CVE-2024-36259
CVE-2024-36259
Description
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
717.0+ 1 more
- (no CPE)range: 17.0
- (no CPE)range: master
Patches
Vulnerability mechanics
References
1- github.com/odoo/odoo/issues/199330nvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.