Exposición de Odoo

CMS
22
score de exposición
9554
sitios usan
0
en explotación
1
críticos
Análisis Vexday

O histórico de vulnerabilidades do Odoo reúne 34 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo KEV — nenhuma das falhas registradas consta atualmente como explorada ativamente pela CISA. A falha mais crítica em evidência, CVE-2018-15640, apresenta EPSS de aproximadamente 0,079, indicando probabilidade baixa a moderada de exploração em curto prazo, e está associada ao padrão de controle de acesso inadequado (CWE-284), que é justamente o tipo de fraqueza mais recorrente no portfólio de vulnerabilidades da plataforma. A ausência de novas CVEs nos últimos 90 dias e a existência de apenas uma falha de severidade crítica sugerem superfície de ataque relativamente estável no período recente, embora controles de autorização devam receber atenção prioritária em revisões de segurança, dado o padrão de falha dominante.

CVEs

34 resultados
CVE-2018-15638HIGHCross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attacEPSS 0.7%CVE-2021-44547HIGHA sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading tEPSS 0.7%CVE-2024-12368HIGHImproper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuthEPSS 0.7%CVE-2024-36259HIGHImproper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensEPSS 0.7%CVE-2021-44460HIGHImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to acEPSS 0.7%CVE-2021-45071MEDIUMCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbEPSS 0.7%CVE-2021-23166HIGHA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and wEPSS 0.6%CVE-2021-23186HIGHA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access andEPSS 0.6%CVE-2021-23178HIGHImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online paymentsEPSS 0.6%CVE-2021-26263HIGHCross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote atEPSS 0.6%CVE-2021-44775MEDIUMCross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attacEPSS 0.5%CVE-2021-44461MEDIUMCross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control theEPSS 0.5%CVE-2021-44476MEDIUMA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read localEPSS 0.5%CVE-2021-44465MEDIUMImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe EPSS 0.5%