Improper Access Control Vulnerability in Odoo Community and Enterprise
CVE-2019-11785

6.5MEDIUM

Key Information:

Vendor

Odoo

Vendor
CVE Published:
22 December 2020

What is CVE-2019-11785?

A vulnerability in Odoo's mail module allows remote authenticated users to exploit improper access control, gaining unauthorized access to messages associated with business records. This flaw enables users to view messages they should not have permission to access and to subscribe for future notifications regarding these messages, potentially leading to sensitive information disclosure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Odoo Community <= 13.0

Odoo Enterprise <= 13.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nils Hamerlinck (Trobz)
.