Record summary

CVE-2017-9416 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOdoo 8.0/9.0/10.0 - Local File InclusionCVSS 6.5

Odoo 8.0, 9.0, and 10.0 are susceptible to local file inclusion via tools.file_open. An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Allows an attacker to read arbitrary files on the server.

Remediation

Upgrade to a patched version of Odoo or apply the necessary security patches.

WeaknessesCWE-22
AuthorsCo5mos
Template tagscve2017cveodoolfivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:odoo:odoo:8.0:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:odoo:odoo"
Shodan: http.title:"odoo"
FOFA: title="odoo"
Google: intitle:"odoo"

Source: ProjectDiscovery

References

2