Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.
References
Link Resource
https://github.com/odoo/odoo/issues/32508 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-03T18:53:59

Updated: 2019-07-03T18:53:59

Reserved: 2018-08-02T00:00:00


Link: CVE-2018-14863

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-07-03T19:15:10.643

Modified: 2019-07-05T18:15:49.117


Link: CVE-2018-14863

JSON object: View

cve-icon Redhat Information

No data.

CWE