Vulnerabilities > Odoo > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-25 CVE-2021-23166 Unspecified vulnerability in Odoo
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
network
low complexity
odoo
8.7
2023-04-25 CVE-2021-23178 Unspecified vulnerability in Odoo
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
network
low complexity
odoo
7.5
2023-04-25 CVE-2021-23186 Unspecified vulnerability in Odoo
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenants, in a multi-tenant system.
network
low complexity
odoo
8.7
2023-04-25 CVE-2021-23203 Unspecified vulnerability in Odoo 14.0/15.0
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
network
low complexity
odoo
7.5
2023-04-25 CVE-2021-45111 Unspecified vulnerability in Odoo
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
network
low complexity
odoo
8.1
2020-12-22 CVE-2020-29396 Unspecified vulnerability in Odoo 11.0/12.0/13.0
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.
network
low complexity
odoo
8.8
2020-12-22 CVE-2018-15632 Improper Input Validation vulnerability in Odoo 10.0/11.0/8.0
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
network
low complexity
odoo CWE-20
8.5
2019-06-28 CVE-2018-14885 Improper Access Control vulnerability in Odoo 10.0/11.0
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password.
network
low complexity
odoo CWE-284
7.5
2017-07-04 CVE-2017-10804 Missing Authentication for Critical Function vulnerability in Odoo 10.0/8.0/9.0
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer.
network
low complexity
odoo CWE-306
7.5
2017-07-04 CVE-2017-10803 Deserialization of Untrusted Data vulnerability in Odoo 10.0/8.0/9.0
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
network
odoo CWE-502
8.5