CVE-2024-34534: Odoo

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model.

Affected products

  • Odoo Odoo: from 16.0, before 16.0.1 (fixed in 16.0.1)

Published 2024-05-06. Last modified 2026-06-17.