Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vh48-8j6v-g2m7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

EPSS

Процентиль: 45%
0.00224
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 6 лет назад

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

CVSS3: 8.1
nvd
около 6 лет назад

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

CVSS3: 8.1
debian
около 6 лет назад

Improper access control in the computed fields system of the framework ...

CVSS3: 8.1
fstec
около 6 лет назад

Уязвимость CRM-системы Odoo Community Edition и ERP-системы Odoo Enterprise Edition, связанная с ошибками обработки несохраненных вычисляемых полей от имени суперпользователя, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 45%
0.00224
Низкий