CVE-2019-11783
Summary
| CVE | CVE-2019-11783 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-22 17:15:00 UTC |
| Updated | 2021-10-28 16:18:00 UTC |
| Description | Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SEC] CVE-2019-11783 - Affects: Odoo 14.0 and earlier (Community an... · Issue #63708 · odoo/odoo · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Nils Hamerlinck (Trobz)
LEGACY: Christopher Riis Bubeck Eriksen
LEGACY: Alexandre Diaz
LEGACY: "Raspina Net Pars Group"
There are currently no legacy QID mappings associated with this CVE.