Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
References
Link | Resource |
---|---|
https://github.com/odoo/odoo/commits/master | Third Party Advisory |
https://github.com/odoo/odoo/issues/32507 | Patch Third Party Advisory |
https://github.com/odoo/odoo/commits/master | Third Party Advisory |
https://github.com/odoo/odoo/issues/32507 | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/odoo/odoo/commits/master - Third Party Advisory | |
References | () https://github.com/odoo/odoo/issues/32507 - Patch, Third Party Advisory |
Information
Published : 2019-06-28 18:15
Updated : 2024-11-21 03:49
NVD link : CVE-2018-14868
Mitre link : CVE-2018-14868
CVE.ORG link : CVE-2018-14868
JSON object : View
Products Affected
odoo
- odoo
CWE
CWE-287
Improper Authentication