Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3g3-3qwm-w95x

Опубликовано: 25 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

EPSS

Процентиль: 35%
0.00144
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

CVSS3: 7.5
nvd
12 месяцев назад

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

CVSS3: 7.5
debian
12 месяцев назад

Improper access control in mail module of Odoo Community 17.0 and Odoo ...

EPSS

Процентиль: 35%
0.00144
Низкий

7.5 High

CVSS3

Дефекты

CWE-284