[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5399-1 odoo -- odoo

ID: oval:org.secpod.oval:def:610537Date: (C)2023-05-12   (M)2023-05-12
Class: PATCHFamily: unix




Several vulnerabilities were discovered in odoo, a suite of web based open source business apps. CVE-2021-44775, CVE-2021-26947, CVE-2021-45071, CVE-2021-26263: XSS allowing remote attacker to inject arbitrary commands. CVE-2021-45111: Incorrect access control allowing authenticated remote user to create user accounts and access restricted data. CVE-2021-44476, CVE-2021-23166: Incorrect access control allowing authenticated remote administrator to access local files on the server. CVE-2021-23186: Incorrect access control allowing authenticated remote administrator to modify database contents of other tenants. CVE-2021-23178: Incorrect access control allowing authenticated remote user to use another user"s payment method. CVE-2021-23176: Incorrect access control allowing authenticated remote user to access accounting information. CVE-2021-23203: Incorrect access control allowing authenticated remote user to access arbitrary documents via PDF exports.

Platform:
Debian 11.x
Product:
odoo-14
Reference:
DSA-5399-1
CVE-2021-23166
CVE-2021-23176
CVE-2021-23178
CVE-2021-23186
CVE-2021-23203
CVE-2021-26263
CVE-2021-26947
CVE-2021-44476
CVE-2021-44775
CVE-2021-45071
CVE-2021-45111
CVE    11
CVE-2021-23186
CVE-2021-23176
CVE-2021-23166
CVE-2021-23178
...

© SecPod Technologies