Skip to content
Noroxi

Odoo records

56 published records for vendor odoo.

All records

56 records
  • In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under

    CriticalCVSS 9.8No exploitEPSS 3%

    odoo · odooJul 4, 2017

  • Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote

    CriticalCVSS 9.8No exploitEPSS 2%

    odoo · odooJun 28, 2019

  • SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-atten

    CriticalCVSS 9.8No exploitEPSS 1%

    odoo · biometric attendanceDec 14, 2023

  • Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated pr

    HighCVSS 8.8No exploitEPSS 8%

    odoo · odooApr 9, 2019

  • Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticat

    CriticalCVSS 9.1No exploitEPSS 2%

    odoo · odooJul 3, 2019

  • A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows

    HighCVSS 8.8No exploitEPSS 3%

    odoo · odooDec 22, 2020

  • Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attacke

    HighCVSS 8.8No exploitEPSS 2%

    odoo · odooDec 22, 2020

  • Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote

    CriticalCVSS 9.1No exploitEPSS 1%

    odoo · odooDec 22, 2020

  • A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading t

    CriticalCVSS 9.1No exploitEPSS 1%

    odoo · odooApr 25, 2023

  • In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the

    HighCVSS 8.8No exploitEPSS 1%

    odoo · odooJul 4, 2017

  • Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth

    HighCVSS 8.8No exploitEPSS 1%

    odoo · odooFeb 25, 2025

  • A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and w

    HighCVSS 8.7No exploitEPSS 1%

    odoo · odooApr 25, 2023

  • A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and

    HighCVSS 8.7No exploitEPSS 1%

    odoo · odooApr 25, 2023

  • Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authent

    HighCVSS 8.1No exploitEPSS 2%

    odoo · odooDec 19, 2019

  • Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows auth

    HighCVSS 8.1No exploitEPSS 1%

    odoo · odooJul 3, 2019

  • Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated u

    HighCVSS 8.1No exploitEPSS 1%

    odoo · odooJul 3, 2019

  • Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger

    HighCVSS 8.1No exploitEPSS 1%

    odoo · odooApr 25, 2023

  • The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression

    HighCVSS 7.5No exploitEPSS 2%

    odoo · odooJul 5, 2019

  • Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attack

    HighCVSS 7.5No exploitEPSS 1%

    odoo · odooApr 25, 2023

  • Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments

    HighCVSS 7.5No exploitEPSS 1%

    odoo · odooApr 25, 2023

  • A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a

    HighCVSS 7.3No exploitEPSS 1%

    May 6, 2024

  • A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote at

    HighCVSS 7.3No exploitEPSS 0%

    May 6, 2024

  • CVE-2017-9416
    28Monitor

    Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local fi

    MediumCVSS 6.5Proof of conceptEPSS 6%

    odoo · odooJun 4, 2017

  • In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the D

    MediumCVSS 6.5Proof of conceptEPSS 4%

    odoo · odooJul 4, 2017

  • Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier

    MediumCVSS 6.5No exploitEPSS 2%

    odoo · odooJun 28, 2019