CVE-2018-15645

MEDIUM

Odoo < 12.0 - Improper Access Control

Title source: rule
STIX 2.1

Description

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/odoo/odoo/issues/63705

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284 CWE-732
Status published
Products (1)
odoo/odoo < 12.0 (2 CPE variants)
Published Dec 22, 2020
Tracked Since Feb 18, 2026