Vulnerability Description
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
CVSS Score
5.4
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Odoo | Odoo | 8.0 |
Related Weaknesses (CWE)
References
- https://sysdream.com/news/lab/2017-11-20-cve-2017-5871-odoo-url-redirection-to-dExploitThird Party Advisory
- https://www.odoo.comVendor Advisory
- https://sysdream.com/news/lab/2017-11-20-cve-2017-5871-odoo-url-redirection-to-dExploitThird Party Advisory
- https://www.odoo.comVendor Advisory
FAQ
What is CVE-2017-5871?
CVE-2017-5871 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
How severe is CVE-2017-5871?
CVE-2017-5871 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5871?
Check the references section above for vendor advisories and patch information. Affected products include: Odoo Odoo.