Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jr5f-4v8f-4m67

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

EPSS

Процентиль: 68%
0.00576
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 5 лет назад

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

CVSS3: 9.1
nvd
около 5 лет назад

Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

CVSS3: 9.1
debian
около 5 лет назад

Improper input validation in database creation logic in Odoo Community ...

EPSS

Процентиль: 68%
0.00576
Низкий

Дефекты

CWE-20