PT-2019-9150 · Odoo+1 · Odoo Enterprise+1
Jérôme Maes
+1
·
Publicado
2019-04-09
·
Atualizado
2021-02-08
·
CVE-2018-15640
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Odoo Enterprise versions 10.0 through 12.0
Description
The issue is related to improper access control in the Helpdesk App, allowing remote authenticated attackers to gain elevated privileges by sending a crafted request.
Recommendations
For Odoo Enterprise versions 10.0 through 12.0, update to a version that includes a fix for this issue to prevent exploitation.
Correção
Incorrect Authorization
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Odoo Enterprise