CVE-2018-14867: Medium severity odoo vulnerability
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14867?
CVE-2018-14867 is a vulnerability in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0.
What is the severity of CVE-2018-14867?
The severity of CVE-2018-14867 is medium with a CVSS score of 5.3.
How does CVE-2018-14867 affect Odoo?
CVE-2018-14867 allows remote attackers to post messages on behalf of customers and to guess document attribute values via crafted parameters in the portal messaging system.
Which versions of Odoo are affected by CVE-2018-14867?
Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 are affected by CVE-2018-14867.
How can I fix CVE-2018-14867?
To fix CVE-2018-14867, it is recommended to apply the latest security patches provided by Odoo.