Database Access Control Flaw in Odoo Products
CVE-2018-14885
9.8CRITICAL
What is CVE-2018-14885?
The Odoo platform has a significant flaw in its database manager component affecting both Community and Enterprise versions 10.0 and 11.0. This vulnerability enables remote attackers to restore a database dump without requiring super-admin credentials, potentially exposing sensitive information. The issue arises from inadequate access controls, allowing an arbitrary password to succeed in the restoration process, thus bypassing the intended authentication mechanisms.