Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11785

Опубликовано: 22 дек. 2020
Источник: nvd
CVSS3: 6.5
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*
Версия до 13.0 (включая)
cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*
Версия до 13.0 (включая)

EPSS

Процентиль: 42%
0.00198
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284
CWE-862

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.

CVSS3: 4.3
debian
около 5 лет назад

Improper access control in mail module (followers) in Odoo Community 1 ...

github
больше 3 лет назад

Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.

EPSS

Процентиль: 42%
0.00198
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284
CWE-862