Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Andrew Grasso

#49744of 55,141
5.3Total CVSS
Vulnerabilities · 1
PT-2019-9065
5.3
2019-06-28
Odoo · Odoo Community · CVE-2018-14867
**Name of the Vulnerable Software and Affected Versions** Odoo Community versions 9.0 through 10.0 Odoo Enterprise versions 9.0 through 10.0 **Description** The issue is related to incorrect access control in the portal messaging system, allowing remote attackers to post messages on behalf of customers and guess document attribute values via crafted parameters. **Recommendations** For Odoo Community versions 9.0 through 10.0, consider restricting access to the portal messaging system until a fix is available. For Odoo Enterprise versions 9.0 through 10.0, consider restricting access to the portal messaging system until a fix is available. As a temporary workaround, consider disabling the use of crafted parameters in the portal messaging system to minimize the risk of exploitation.