Improper Access Control in Odoo Email Module Affects Odoo Community and Enterprise
CVE-2024-36259

6.5MEDIUM

Key Information:

Vendor

Odoo

Vendor
CVE Published:
25 February 2025

What is CVE-2024-36259?

A vulnerability in the mail module of Odoo's Community and Enterprise versions allows remote authenticated attackers to exploit improper access control mechanisms. By executing a specially crafted oracle-based attack, these attackers can extract sensitive information from the affected systems. This security flaw highlights the need for stringent access controls in software documentation and implementation.

Affected Version(s)

Odoo Community master <= 17.0

Odoo Enterprise master <= 17.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bram Van Gaal
.