Vulnerabilities > CVE-2018-15640 - Incorrect Authorization vulnerability in Odoo 10.0/11.0/12.0

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
odoo
CWE-863

Summary

Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.

Vulnerable Configurations

Part Description Count
Application
Odoo
3

Common Weakness Enumeration (CWE)