CVE-2018-14887

Description

Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and to disclose database names via a crafted request.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS Score
Exploitation Probability
0.431

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Odoo 10.0Windows
Multiple Vulnerabilities are affected in Odoo 9.0Windows
Multiple Vulnerabilities are affected in Odoo 11.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234