Vulnerabilities > Odoo > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-25 | CVE-2021-23166 | Unspecified vulnerability in Odoo A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server. | 8.7 |
2023-04-25 | CVE-2021-23178 | Unspecified vulnerability in Odoo Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead. | 7.5 |
2023-04-25 | CVE-2021-23186 | Unspecified vulnerability in Odoo A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system. | 8.7 |
2023-04-25 | CVE-2021-23203 | Unspecified vulnerability in Odoo 14.0/15.0 Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests. | 7.5 |
2023-04-25 | CVE-2021-45111 | Unspecified vulnerability in Odoo Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials. | 8.1 |
2020-12-22 | CVE-2020-29396 | Unspecified vulnerability in Odoo 11.0/12.0/13.0 A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation. | 8.8 |
2020-12-22 | CVE-2019-11781 | Improper Input Validation vulnerability in Odoo Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation. | 8.8 |
2019-12-19 | CVE-2019-11780 | Unspecified vulnerability in Odoo 13.0 Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation. | 8.1 |
2019-07-05 | CVE-2018-14733 | Improper Input Validation vulnerability in Odoo The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances. | 7.5 |
2019-07-03 | CVE-2018-14859 | Improper Access Control vulnerability in Odoo 10.0/11.0/9.0 Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token. | 8.1 |