PT-2020-9202 · Odoo+1 · Odoo Community+2

Iamsushi

·

Published

2020-12-22

·

Updated

2021-02-08

·

CVE-2019-11781

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Odoo Community versions prior to 13.0 Odoo Enterprise versions prior to 13.0
Description The issue is related to improper input validation in the portal component, allowing remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
Recommendations For Odoo Community versions prior to 13.0, update to version 13.0 or later to resolve the issue. For Odoo Enterprise versions prior to 13.0, update to version 13.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the portal component to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1048
ALT-PU-2021-1236
CVE-2019-11781

Affected Products

Alt Linux
Odoo Community
Odoo Enterprise