ZeroHour

CVE-2018-15645

CVSS 3.1
6.5 medium
EPSS
<1%p57
Published
()
Modified
Description

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.

Vendors
odoo
Products
odoo
Weakness
CWE-284, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.