PT-2019-9065 · Odoo · Odoo Community+1

Andrew Grasso

+2

·

Published

2019-06-28

·

Updated

2019-07-05

·

CVE-2018-14867

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Odoo Community versions 9.0 through 10.0 Odoo Enterprise versions 9.0 through 10.0
Description The issue is related to incorrect access control in the portal messaging system, allowing remote attackers to post messages on behalf of customers and guess document attribute values via crafted parameters.
Recommendations For Odoo Community versions 9.0 through 10.0, consider restricting access to the portal messaging system until a fix is available. For Odoo Enterprise versions 9.0 through 10.0, consider restricting access to the portal messaging system until a fix is available. As a temporary workaround, consider disabling the use of crafted parameters in the portal messaging system to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14867

Affected Products

Odoo Community
Odoo Enterprise