First published: Fri Jun 28 2019(Updated: )
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | =9.0 | |
Odoo Odoo | =9.0 | |
Odoo Odoo | =10.0 | |
Odoo Odoo | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14867 is a vulnerability in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0.
The severity of CVE-2018-14867 is medium with a CVSS score of 5.3.
CVE-2018-14867 allows remote attackers to post messages on behalf of customers and to guess document attribute values via crafted parameters in the portal messaging system.
Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 are affected by CVE-2018-14867.
To fix CVE-2018-14867, it is recommended to apply the latest security patches provided by Odoo.