TROYANOSYVIRUS
Back to CVEs

CVE-2019-11780

HIGH
8.1

Description

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

CVE Details

CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published12/19/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

odoo:odoo

Weaknesses (CWE)

CWE-284

References

https://github.com/odoo/odoo/issues/42196(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.