First published: Tue Apr 09 2019(Updated: )
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=12.0 | |
Odoo Odoo | <=12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-15631.
The severity of CVE-2018-15631 is medium with a severity value of 6.5.
Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier are affected by CVE-2018-15631.
Remote authenticated attackers can e-mail themselves arbitrary files from the database via a crafted RPC request.
Yes, a fix is available for CVE-2018-15631. Users should update to a version that includes the fix.