Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-14859

Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.9%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.5
Products affected by CVE-2018-14859
  • Odoo » Odoo » Version: 10.0
    cpe:2.3:a:odoo:odoo:10.0
  • Odoo » Odoo » Version: 11.0
    cpe:2.3:a:odoo:odoo:11.0
  • Odoo » Odoo » Version: 9.0
    cpe:2.3:a:odoo:odoo:9.0


Contact Us

Shodan ® - All rights reserved