vendor:
Odoo
by:
Emre ÖVÜNÇ
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Odoo
Affected Version From: v12.0
Affected Version To: v12.0
Patch Exists: YES
Related CWE: N/A
CPE: a:odoo:odoo
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows/Linux
2019
Odoo 12.0 – Local File Inclusion
Odoo 12.0 is vulnerable to Local File Inclusion (LFI) attacks. An attacker can exploit this vulnerability by sending a crafted HTTP request to the target server. The attacker can use the 'base_import/static/c:/windows/win.ini', 'web/static/c:/windows/win.ini' and 'base/static/c:/windows/win.ini' requests to get some information from the target.
Mitigation:
The vendor has released a security patch to address this vulnerability. It is recommended to update the Odoo software to the latest version.