Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6gp-grvf-r987

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

EPSS

Процентиль: 56%
0.00333
Низкий

Дефекты

CWE-732
CWE-862

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

CVSS3: 6.5
nvd
около 5 лет назад

Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

CVSS3: 6.5
debian
около 5 лет назад

Improper access control in mail module (channel partners) in Odoo Comm ...

EPSS

Процентиль: 56%
0.00333
Низкий

Дефекты

CWE-732
CWE-862