CVE-2024-34533: Odoo
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZITools::query_fetch, or IZITools::query_execute.
Affected products
- Odoo Odoo: from 11.0, before 17.0.3 (fixed in 17.0.3)
Published 2024-05-06. Last modified 2026-06-17.