Vulnerabilidades em Odoo
34 resultadosAnálise Vexday
Odoo apresenta 34 vulnerabilidades catalogadas, com apenas 1 crítica (CVSS) e nenhuma sob exploração ativa conhecida, reduzindo o risco imediato. A fraqueza dominante (CWE-284 - controle de acesso inadequado) sugere problemas estruturais em permissões, mas a ausência de publicações recentes indica estabilidade relativa na superfície de ataque. O risco concentra-se em vulnerabilidades legacy que requerem avaliação de seu impacto específico no ambiente do usuário.
CVE-2019-11786MEDIUMImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modifyEPSS 0.7%CVE-2018-15638HIGHCross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attacEPSS 0.7%CVE-2021-44460HIGHImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to acEPSS 0.7%CVE-2024-12368HIGHImproper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuthEPSS 0.7%CVE-2024-36259HIGHImproper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensEPSS 0.7%CVE-2021-45071MEDIUMCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbEPSS 0.7%CVE-2021-23166HIGHA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and wEPSS 0.6%CVE-2021-23186HIGHA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access andEPSS 0.6%CVE-2021-23178HIGHImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online paymentsEPSS 0.6%CVE-2021-26263HIGHCross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote atEPSS 0.6%CVE-2021-44775MEDIUMCross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attacEPSS 0.5%CVE-2021-44461MEDIUMCross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control theEPSS 0.5%CVE-2021-44476MEDIUMA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read localEPSS 0.5%CVE-2021-44465MEDIUMImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe EPSS 0.5%