VYPR

Vendor CVEs

Odcms

All CVEs

57 total · sorted by risk
  • CVE-2018-14886MedJun 28, 2019
    risk 0.32cvss 4.9epss 0.01

    The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.

  • CVE-2021-44465MedApr 25, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.

  • CVE-2019-11786MedDec 22, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.

  • CVE-2019-11785MedDec 22, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future…

  • CVE-2018-14866MedJul 3, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.

  • CVE-2010-2345Jun 21, 2010
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests.

  • CVE-2010-2344Jun 21, 2010
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Page parameter to (1) _main/index.php, (2) _members/index.php, (3) _forum/index.php, (4) _docs/index.php, and (5)…

Page 2 of 2