Vulnerabilities > Odoo > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-28 | CVE-2018-14867 | Improper Access Control vulnerability in Odoo 10.0/9.0 Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters. | 5.0 |
2019-05-22 | CVE-2017-5871 | Open Redirect vulnerability in Odoo 10.0/8.0/9.0 Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. | 5.8 |
2019-04-09 | CVE-2018-15635 | Cross-site Scripting vulnerability in Odoo Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name. | 4.3 |
2019-04-09 | CVE-2018-15631 | Unspecified vulnerability in Odoo Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request. | 4.0 |
2017-07-04 | CVE-2017-10805 | Incorrect Authorization vulnerability in Odoo 10.0/8.0/9.0 In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users. | 6.5 |
2017-06-04 | CVE-2017-9416 | Path Traversal vulnerability in Odoo 10.0/8.0/9.0 Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service. | 4.0 |