CVE-2018-14862

MEDIUM

Odoo 11.0 Authenticated Arbitrary Menu Item Deletion via Mail Templating RPC

Title source: llm
STIX 2.1

Description

Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/odoo/odoo/issues/32504

Scores

CVSS v3 6.5
EPSS 0.0080
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-732
Status published
Products (3)
odoo/odoo 9.0 (2 CPE variants)
odoo/odoo 10.0 (2 CPE variants)
odoo/odoo 11.0 (2 CPE variants)
Published Jul 03, 2019
Tracked Since Feb 18, 2026