Improper Access Control in Odoo Email Module Affects Odoo Community and Enterprise
CVE-2024-36259

7.5HIGH

Key Information:

Vendor
Odoo
Status
Odoo Community
Odoo Enterprise
Vendor
CVE Published:
25 February 2025

Summary

A vulnerability in the mail module of Odoo's Community and Enterprise versions allows remote authenticated attackers to exploit improper access control mechanisms. By executing a specially crafted oracle-based attack, these attackers can extract sensitive information from the affected systems. This security flaw highlights the need for stringent access controls in software documentation and implementation.

Affected Version(s)

Odoo Community master <= 17.0

Odoo Enterprise master <= 17.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bram Van Gaal
.