Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: odoo
Published: 2019-04-09T15:41:20
Updated: 2024-08-05T10:01:54.359Z
Reserved: 2018-08-21T00:00:00
Link: CVE-2018-15631
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-04-09T16:29:01.087
Modified: 2024-11-21T03:51:11.497
Link: CVE-2018-15631
Redhat
No data.