CVE-2024-36259: High severity odoo vulnerability
Published Feb 25, 2025
·Updated
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
Affected Software
4 affected components
Odoo Odoo=17.0
Odoo Odoo=17.0
Odoo Community
Odoo Enterprise
Event History
Feb 25, 2025
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36259?
The severity of CVE-2024-36259 is classified as high due to its potential to expose sensitive information.
2
How do I fix CVE-2024-36259?
To fix CVE-2024-36259, apply the latest security patches from Odoo for both the Community and Enterprise versions.
3
Who is affected by CVE-2024-36259?
CVE-2024-36259 affects users of Odoo Community 17.0 and Odoo Enterprise 17.0.
4
What type of attack does CVE-2024-36259 allow?
CVE-2024-36259 allows remote authenticated attackers to extract sensitive information via an oracle-based crafted attack.
5
Can CVE-2024-36259 be exploited by unauthenticated users?
No, CVE-2024-36259 requires authenticated access for exploitation.