Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
odoo odoo 9.0 vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2018-14866
Incorrect access control in the TransientModel framework in Odoo Community 11.0 and previous versions and Odoo Enterprise 11.0 and previous versions allows authenticated malicious users to access data in transient records that they do not own by making an RPC call before garbage ...
Odoo Odoo 9.0
Odoo Odoo 11.0
Odoo Odoo 10.0
4
CVSSv2
CVE-2018-14886
The module-description renderer in Odoo Community 11.0 and previous versions and Odoo Enterprise 11.0 and previous versions does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description.
Odoo Odoo 9.0
Odoo Odoo 10.0
Odoo Odoo 11.0
5.8
CVSSv2
CVE-2018-14887
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and previous versions and Odoo Enterprise 11.0 and previous versions allows a remote malicious user to deny access to the service and to disclose database names via a crafted request.
Odoo Odoo 10.0
Odoo Odoo 9.0
Odoo Odoo 11.0
5.8
CVSSv2
CVE-2017-5871
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
Odoo Odoo 8.0
Odoo Odoo 10.0
Odoo Odoo 9.0
5
CVSSv2
CVE-2018-14867
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote malicious users to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
Odoo Odoo 9.0
Odoo Odoo 10.0
4
CVSSv2
CVE-2018-14868
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
Odoo Odoo 9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2