CVE-2019-11780

Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.
References
Link Resource
https://github.com/odoo/odoo/issues/42196 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:odoo:odoo:13.0:*:*:*:community:*:*:*
cpe:2.3:a:odoo:odoo:13.0:*:*:*:enterprise:*:*:*

History

02 Nov 2021, 19:14

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

Information

Published : 2019-12-19 16:16

Updated : 2023-12-10 13:13


NVD link : CVE-2019-11780

Mitre link : CVE-2019-11780

CVE.ORG link : CVE-2019-11780


JSON object : View

Products Affected

odoo

  • odoo
CWE
NVD-CWE-Other CWE-284

Improper Access Control