CVE-2018-15645: High severity odoo vulnerability
Published Dec 22, 2020
·Updated
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
Affected Software
2 affected components
Odoo<=12.0
Odoo<=12.0
Remediation
Patch Available
Event History
Dec 22, 2020
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-15645.
2
What is the severity of CVE-2018-15645?
The severity of CVE-2018-15645 is high with a score of 6.5.
3
What is the affected software?
The affected software is Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier.
4
How can remote authenticated users exploit this vulnerability?
Remote authenticated users can exploit this vulnerability by creating arbitrary records via crafted payloads.
5
Is privilege escalation possible with this vulnerability?
Yes, privilege escalation may be possible with this vulnerability.