mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 23:28:04 +02:00
18 lines
698 B
Markdown
18 lines
698 B
Markdown
### [CVE-2018-14868](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14868)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenticated users to change the password of other users without knowing their current password via a crafted RPC call.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/odoo/odoo/commits/master
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|