Security Advisory

CVE-2024-36259

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-02-25 19:10:40
Last updated 2025-02-25 19:39:18
Assigner odoo
CVSS score 7.5
State PUBLISHED

Description

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.