Vulnerabilities > Odoo > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-25 CVE-2021-23166 Unspecified vulnerability in Odoo
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
network
low complexity
odoo
8.7
2023-04-25 CVE-2021-23178 Unspecified vulnerability in Odoo
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
network
low complexity
odoo
7.5
2023-04-25 CVE-2021-23186 Unspecified vulnerability in Odoo
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.
network
low complexity
odoo
8.7
2023-04-25 CVE-2021-23203 Unspecified vulnerability in Odoo 14.0/15.0
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
network
low complexity
odoo
7.5
2023-04-25 CVE-2021-45111 Unspecified vulnerability in Odoo
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
network
low complexity
odoo
8.1
2020-12-22 CVE-2020-29396 Unspecified vulnerability in Odoo 11.0/12.0/13.0
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.
network
low complexity
odoo
8.8
2020-12-22 CVE-2019-11781 Improper Input Validation vulnerability in Odoo
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
network
low complexity
odoo CWE-20
8.8
2019-12-19 CVE-2019-11780 Unspecified vulnerability in Odoo 13.0
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.
network
low complexity
odoo
8.1
2019-07-05 CVE-2018-14733 Improper Input Validation vulnerability in Odoo
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.
network
low complexity
odoo CWE-20
7.5
2019-07-03 CVE-2018-14859 Improper Access Control vulnerability in Odoo 10.0/11.0/9.0
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.
network
low complexity
odoo CWE-284
8.1