Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-14867


Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.


Published

2019-06-28T18:15:10.410

Last Modified

2024-11-21T03:49:57.800

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application odoo odoo 9.0 Yes
Application odoo odoo 9.0 Yes
Application odoo odoo 10.0 Yes
Application odoo odoo 10.0 Yes

References