Vulnerability Description
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Odoo | Odoo | 9.0 |
Related Weaknesses (CWE)
References
- https://github.com/odoo/odoo/commits/masterThird Party Advisory
- https://github.com/odoo/odoo/issues/32507PatchThird Party Advisory
- https://github.com/odoo/odoo/commits/masterThird Party Advisory
- https://github.com/odoo/odoo/issues/32507PatchThird Party Advisory
FAQ
What is CVE-2018-14868?
CVE-2018-14868 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current ...
How severe is CVE-2018-14868?
CVE-2018-14868 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14868?
Check the references section above for vendor advisories and patch information. Affected products include: Odoo Odoo.