CVE-2018-14862: Medium severity odoo vulnerability
Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14862?
CVE-2018-14862 is a vulnerability in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier that allows authenticated internal users to delete arbitrary menuitems.
How can this vulnerability be exploited?
This vulnerability can be exploited by authenticated internal users who can send a crafted RPC request to delete arbitrary menuitems.
What is the severity of CVE-2018-14862?
The severity of CVE-2018-14862 is medium with a score of 6.5.
Which versions of Odoo are affected by this vulnerability?
Odoo Community 11.0 and earlier, as well as Odoo Enterprise 11.0 and earlier, are affected by this vulnerability.
Is there a fix available for CVE-2018-14862?
Yes, it is recommended to upgrade to a fixed version of Odoo to mitigate this vulnerability.