vendor:
Odoo CRM
by:
An independent security researcher
6,5
CVSS
MEDIUM
Arbitrary Python Code Execution
502
CWE
Product Name: Odoo CRM
Affected Version From: 10.0
Affected Version To: 10.0
Patch Exists: YES
Related CWE: CVE-2017-10803
CPE: a:odoo:odoo
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Arbitrary Python Code Execution in Odoo CRM version 10.0
An independent security researcher has reported a vulnerability in Odoo CRM version 10.0 which allows an administrator to execute arbitrary Python code with the same privilege level as the Odoo webapp by anonymizing the database then attempt the de-anonymization process with a crafted pickle file.
Mitigation:
Odoo has done a private disclosure for the issue and the patch was merged in all supported branches.