First published: Tue Dec 22 2020(Updated: )
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=12.0 | |
Odoo Odoo | <=12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-11781.
CVE-2019-11781 is an improper input validation vulnerability in the portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, which allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier are affected by this vulnerability.
The severity rating of CVE-2019-11781 vulnerability is high (8.8).
To fix CVE-2019-11781 vulnerability, update Odoo to the latest version available and apply any patches provided by the vendor.