ZeroHour

CVE-2018-14862

CVSS 3.0
6.5 medium
EPSS
<1%p55
Published
()
Modified
Description

Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

Vendors
odoo
Products
odoo
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.