Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/odoo/odoo/issues/32505 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-03T19:01:53
Updated: 2024-08-05T09:38:13.948Z
Reserved: 2018-08-02T00:00:00
Link: CVE-2018-14860
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-07-03T20:15:10.837
Modified: 2024-11-21T03:49:56.583
Link: CVE-2018-14860
Redhat
No data.