π¨ CVE-2018-15632
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
π@cveNotify
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
π@cveNotify
GitHub
[SEC] CVE-2018-15632 - Affects: Odoo 11.0 and earlier (Community an... Β· Issue #63700 Β· odoo/odoo
Security Advisory - CVE-2018-15632 Affects: Odoo 11.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15632 Component: Framework Credits: P. Valov (SoCyber) Improper input validati...
π¨ CVE-2018-15633
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
π@cveNotify
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
π@cveNotify
GitHub
[SEC] CVE-2018-15633 - Affects: Odoo 11.0 and earlier (Community an... Β· Issue #63701 Β· odoo/odoo
Security Advisory - CVE-2018-15633 Affects: Odoo 11.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15633 Component: "document" module Credits: Nathanael ROTA (...
π¨ CVE-2018-15634
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
π@cveNotify
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
π@cveNotify
GitHub
[SEC] CVE-2018-15634 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63702 Β· odoo/odoo
Security Advisory - CVE-2018-15634 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15634 Component: Framework Credits: Nathanael ROTA (Capgemini) and Alessandro ...
π¨ CVE-2018-15638
Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.
π@cveNotify
Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.
π@cveNotify
GitHub
[SEC] CVE-2018-15638 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63703 Β· odoo/odoo
Security Advisory - CVE-2018-15638 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15638 Component: Discuss Credits: Subash SN and Bharath Kumar (Appsecco), Dipa...
π¨ CVE-2018-15641
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
π@cveNotify
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
π@cveNotify
GitHub
[SEC] CVE-2018-15641 - Affects: Odoo 11.0 through 14.0 (Community a... Β· Issue #63704 Β· odoo/odoo
Security Advisory - CVE-2018-15641 Affects: Odoo 11.0 through 14.0 (Community and Enterprise Editions) CVE ID: CVE-2018-15641 Component: Framework Credits: msg systems ag, Lauri Vakkala (Silverskin...
π¨ CVE-2019-11782
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.
π@cveNotify
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2019-11782 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63707 Β· odoo/odoo
Security Advisory - CVE-2019-11782 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11782 Component: Portal Credits: Damien LESCOS Improper access control in Odoo...
π¨ CVE-2018-15645
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
π@cveNotify
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2018-15645 - Affects: Odoo 12.0 and earlier (Community an... Β· Issue #63705 Β· odoo/odoo
Security Advisory - CVE-2018-15645 Affects: Odoo 12.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15645 Component: Discuss Credits: Nils Hamerlinck (Trobz) Improper access cont...
π¨ CVE-2019-11783
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
π@cveNotify
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
π@cveNotify
GitHub
[SEC] CVE-2019-11783 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63708 Β· odoo/odoo
Security Advisory - CVE-2019-11783 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11783 Component: Discuss Credits: Nils Hamerlinck (Trobz), Christopher Riis Bu...
π¨ CVE-2019-11785
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.
π@cveNotify
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.
π@cveNotify
GitHub
[SEC] CVE-2019-11785 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63710 Β· odoo/odoo
Security Advisory - CVE-2019-11785 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11785 Component: Discuss Credits: Nils Hamerlinck (Trobz) Improper access cont...
π¨ CVE-2020-35624
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
π@cveNotify
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.
π@cveNotify
π¨ CVE-2020-11717
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
π@cveNotify
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
π@cveNotify
Packetstormsecurity
Programi Bilanc Build 007 Release 014 31.01.2020 SQL Injection β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2020-16166
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
π@cveNotify
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
π@cveNotify
π¨ CVE-2020-8995
Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.
π@cveNotify
Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.
π@cveNotify
seclists.org
Full Disclosure: Programi Bilanc - Build 007 Release 014 31.01.2020 - Broken
encryption with guessable static encryption key [CVEβ¦
encryption with guessable static encryption key [CVEβ¦
π¨ CVE-2020-35491
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
π@cveNotify
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
π@cveNotify
Medium
On Jackson CVEs: Donβt Panic β Here is what you need to know
Addendums (19-May-2020, 28-Sep-2019):
π¨ CVE-2020-35151
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
π@cveNotify
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
π@cveNotify
PHPGurukul
Online Marriage Registration System in PHP | Online Marriage Registration Project
Online Marriage Registration System PHP and MySQL, Download Online Marriage Registration System Project in PHP, live Demo Online Marriage Registration Management project with Source Code on PhpGurukul
π¨ CVE-2020-27687
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
π@cveNotify
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
π@cveNotify
Gist
CVE-2020-27687: Host header injection in Thingsboard prior to version 3.2
CVE-2020-27687: Host header injection in Thingsboard prior to version 3.2 - CVE-2020-27687.md
π¨ CVE-2020-20299
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
π@cveNotify
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
π@cveNotify
GitHub
Y4er/Y4er.com
myblog. Contribute to Y4er/Y4er.com development by creating an account on GitHub.
π¨ CVE-2020-35606
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
π@cveNotify
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
π@cveNotify
Packetstormsecurity
Webmin 1.962 Remote Command Execution β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2020-25106
Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.
π@cveNotify
Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.
π@cveNotify
Packetstormsecurity
SUPREMO 4.1.3.2348 Privilege Escalation β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
π¨ CVE-2020-13547
A type confusion vulnerability exists in the JavaScript engine of Foxit Softwareβs Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
π@cveNotify
A type confusion vulnerability exists in the JavaScript engine of Foxit Softwareβs Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.
π@cveNotify
π¨ CVE-2018-7580
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.
π@cveNotify
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.
π@cveNotify
Ilia Shnaidman
CVE-2018-7580 - Philips Hue Denial of Service
``` [+] Credits: Ilia Shnaidman [+] @0x496c on Twitter [+] https://www.iliashn.com