6.5
CVSSv3

CVE-2017-10803

Published: 04/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.5 | Impact Score: 5.9 | Exploitability Score: 0.6
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

odoo odoo 10.0

odoo odoo 9.0

odoo odoo 8.0

Exploits

## Vulnerability Summary The following advisory describe arbitrary Python code execution found in Odoo CRM version 100 Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc Odoo’s unique value proposition is to be at the same time very easy ...