First published: Fri Jun 28 2019(Updated: )
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | =10.0 | |
Odoo Odoo | =10.0 | |
Odoo Odoo | =11.0 | |
Odoo Odoo | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-14885.
The severity of CVE-2018-14885 is critical.
The affected software for CVE-2018-14885 includes Odoo Community 10.0 and 11.0, and Odoo Enterprise 10.0 and 11.0.
CVE-2018-14885 allows a remote attacker to restore a database dump without knowing the super-admin password.
Yes, you can find more information about CVE-2018-14885 in the following references: [GitHub Commits](https://github.com/odoo/odoo/commits/master) and [GitHub Issue](https://github.com/odoo/odoo/issues/32512).