CVE-2024-36259: Odoo
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
Affected products
- Odoo Odoo: version 17.0 only
Published 2025-02-25. Last modified 2026-06-17.