VYPR

Odoo Community

by Odcms

CVEs (16)

  • CVE-2024-36259Feb 25, 2025
    risk 0.00cvss epss 0.00

    Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

  • CVE-2024-12368Feb 25, 2025
    risk 0.00cvss epss 0.00

    Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.

  • CVE-2021-23203Apr 25, 2023
    risk 0.00cvss epss 0.00

    Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

  • CVE-2021-44465Apr 25, 2023
    risk 0.00cvss epss 0.00

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.

  • CVE-2021-23166Apr 25, 2023
    risk 0.00cvss epss 0.00

    A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.

  • CVE-2018-15641Dec 22, 2020
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.

  • CVE-2018-15638Dec 22, 2020
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

  • CVE-2018-15633Dec 22, 2020
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.

  • CVE-2018-15632Dec 22, 2020
    risk 0.00cvss epss 0.01

    Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

  • CVE-2018-14859Jul 3, 2019
    risk 0.00cvss epss 0.00

    Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.

  • CVE-2018-14862Jul 3, 2019
    risk 0.00cvss epss 0.00

    Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

  • CVE-2018-14863Jul 3, 2019
    risk 0.00cvss epss 0.00

    Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.

  • CVE-2018-14864Jul 3, 2019
    risk 0.00cvss epss 0.00

    Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.

  • CVE-2018-14866Jul 3, 2019
    risk 0.00cvss epss 0.00

    Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.

  • CVE-2018-14868Jun 28, 2019
    risk 0.00cvss epss 0.00

    Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.

  • CVE-2018-14887Jun 28, 2019
    risk 0.00cvss epss 0.00

    Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.