Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HOdoo
APPOdoo≤ 11.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-44547CRITICAL9.1PL ✓same product
Privilege escalation przez błąd sandboxingu w Odoo 15.0
CVE-2018-14860CRITICAL9.1PL ✓same product
Odoo – command injection w silniku dynamicznych wyrażeń (RCE)
CVE-2018-14885CRITICAL9.8PL ✓same product
Odoo — błędna kontrola dostępu w menedżerze baz danych
CVE-2017-10804CRITICAL9.8PL ✓same product
Odoo – auth bypass przez truncację parametrów z bajtem null (0x00)
CVE-2024-12368HIGH8.1same product
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an int...