CVE-2019-11783: Medium severity odoo vulnerability
Published Dec 22, 2020
·Updated
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
Affected Software
2 affected components
Odoo<=14.0
Odoo<=14.0
Event History
Dec 22, 2020
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-11783.
2
What is the severity of CVE-2019-11783?
The severity of CVE-2019-11783 is medium with a severity value of 6.5.
3
What is the affected software for CVE-2019-11783?
The affected software for CVE-2019-11783 is Odoo Community 14.0 and earlier, and Odoo Enterprise 14.0 and earlier.
4
How can remote authenticated users exploit CVE-2019-11783?
Remote authenticated users can exploit CVE-2019-11783 by subscribing to arbitrary mail channels uninvited.
5
Is there any fix available for CVE-2019-11783?
Yes, there is a fix available for CVE-2019-11783. It is recommended to update to a version that is not affected by this vulnerability.