cvedb.io
CVE-2017-10803
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2017-07-04T18:29:00.177 · Last modified 2026-06-17T01:00:44.137

Summary

In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.

Affected products

odoo — odoo

Does this affect you?

Add your gear to cvedb and we'll alert you only when odoo ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.