Vulnerabilities > Odoo > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-25 | CVE-2021-23166 | Unspecified vulnerability in Odoo A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server. | 8.7 |
2023-04-25 | CVE-2021-23178 | Unspecified vulnerability in Odoo Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead. | 7.5 |
2023-04-25 | CVE-2021-23186 | Unspecified vulnerability in Odoo A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system. | 8.7 |
2023-04-25 | CVE-2021-23203 | Unspecified vulnerability in Odoo 14.0/15.0 Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests. | 7.5 |
2023-04-25 | CVE-2021-45111 | Unspecified vulnerability in Odoo Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials. | 8.1 |
2020-12-22 | CVE-2020-29396 | Unspecified vulnerability in Odoo 11.0/12.0/13.0 A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation. | 8.8 |
2020-12-22 | CVE-2018-15632 | Improper Input Validation vulnerability in Odoo 10.0/11.0/8.0 Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials. | 8.5 |
2019-06-28 | CVE-2018-14885 | Improper Access Control vulnerability in Odoo 10.0/11.0 Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. | 7.5 |
2017-07-04 | CVE-2017-10804 | Missing Authentication for Critical Function vulnerability in Odoo 10.0/8.0/9.0 In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. | 7.5 |
2017-07-04 | CVE-2017-10803 | Deserialization of Untrusted Data vulnerability in Odoo 10.0/8.0/9.0 In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used. | 8.5 |