Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
References
Link | Resource |
---|---|
https://github.com/odoo/odoo/issues/32507 | Patch Third Party Advisory |
https://github.com/odoo/odoo/commits/master | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-28 11:15
Updated : 2020-08-24 10:37
NVD link : CVE-2018-14868
Mitre link : CVE-2018-14868
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
odoo
- odoo