github.comConfirmation
https://github.com/odoo/odoo/issues/17394 CVE-2017-9416
MEDIUMNuclei
Odoo 8.0/9.0/10.0 - Local File Inclusion
Record summary
CVE-2017-9416 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMOdoo 8.0/9.0/10.0 - Local File InclusionCVSS 6.5
Odoo 8.0, 9.0, and 10.0 are susceptible to local file inclusion via tools.file_open. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Allows an attacker to read arbitrary files on the server.
Remediation
Upgrade to a patched version of Odoo or apply the necessary security patches.
WeaknessesCWE-22
AuthorsCo5mos
Template tagscve2017cveodoolfivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:odoo:odoo:8.0:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:odoo:odoo"
Shodan: http.title:"odoo"
FOFA: title="odoo"
Google: intitle:"odoo"
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9416