Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-9416Path Traversal in Odoo

CWE-22Path Traversal4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
24.0%
top 3.95%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 4
Latest updateMay 17

Description

Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDodoo/odoo10.0, 8.0, 9.0+2
debiandebian/odoo

Patches

🔴Vulnerability Details

1
GHSA
GHSA-vgpg-4fc3-2pr2: Directory traversal vulnerability in tools2022-05-17

💥Exploits & PoCs

1
Nuclei
Odoo 8.0/9.0/10.0 - Local File Inclusion

📋Vendor Advisories

1
Debian
CVE-2017-9416: odoo - Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 ...2017