PT-2019-8582 · Odoo · Odoo

Adel Nettar

+1

·

Published

2019-05-22

·

Updated

2019-05-23

·

CVE-2017-5871

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Odoo versions prior to 8.0-20160726 Odoo version 9
Description The issue allows for open redirection, which can be used to obtain sensitive information remotely. This is related to CWE-601.
Recommendations For Odoo versions prior to 8.0-20160726, update to a version newer than 8.0-20160726 to resolve the issue. For Odoo version 9, there is no information about a newer version that contains a fix for this issue, consider restricting access to sensitive information as a temporary mitigation measure.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5871

Affected Products

Odoo