Vulnerabilities > Odoo > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-28 CVE-2018-14867 Improper Access Control vulnerability in Odoo 10.0/9.0
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
network
low complexity
odoo CWE-284
5.0
2019-05-22 CVE-2017-5871 Open Redirect vulnerability in Odoo 10.0/8.0/9.0
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection.
network
odoo CWE-601
5.8
2019-04-09 CVE-2018-15635 Cross-site Scripting vulnerability in Odoo
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.
network
odoo CWE-79
4.3
2019-04-09 CVE-2018-15631 Unspecified vulnerability in Odoo
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.
network
low complexity
odoo
4.0
2017-07-04 CVE-2017-10805 Incorrect Authorization vulnerability in Odoo 10.0/8.0/9.0
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.
network
low complexity
odoo CWE-863
6.5
2017-06-04 CVE-2017-9416 Path Traversal vulnerability in Odoo 10.0/8.0/9.0
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
network
low complexity
odoo CWE-22
4.0