Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.
2019-07-03T19:15:10.580
2024-11-21T03:49:56.890
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | odoo | odoo | 9.0 | Yes |
Application | odoo | odoo | 9.0 | Yes |
Application | odoo | odoo | 10.0 | Yes |
Application | odoo | odoo | 10.0 | Yes |
Application | odoo | odoo | 11.0 | Yes |
Application | odoo | odoo | 11.0 | Yes |