Improper Access Control Vulnerability in Odoo Community and Enterprise
CVE-2019-11785

6.5MEDIUM

Key Information:

Vendor

Odoo

Vendor
CVE Published:
22 December 2020

What is CVE-2019-11785?

A vulnerability in Odoo's mail module allows remote authenticated users to exploit improper access control, gaining unauthorized access to messages associated with business records. This flaw enables users to view messages they should not have permission to access and to subscribe for future notifications regarding these messages, potentially leading to sensitive information disclosure.

Affected Version(s)

Odoo Community <= 13.0

Odoo Enterprise <= 13.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nils Hamerlinck (Trobz)
.