A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.
References
Link | Resource |
---|---|
https://github.com/gmarczynski/odoo-web-progress/commit/3c867f1cf7447449c81b1aa24ebb1f7ae757489f | Patch |
https://github.com/luvsn/OdZoo/tree/main/exploits/web_progress | Exploit Third Party Advisory |
https://github.com/gmarczynski/odoo-web-progress/commit/3c867f1cf7447449c81b1aa24ebb1f7ae757489f | Patch |
https://github.com/luvsn/OdZoo/tree/main/exploits/web_progress | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/gmarczynski/odoo-web-progress/commit/3c867f1cf7447449c81b1aa24ebb1f7ae757489f - Patch | |
References | () https://github.com/luvsn/OdZoo/tree/main/exploits/web_progress - Exploit, Third Party Advisory |
20 Dec 2023, 17:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gmarczynski:dynamic_progress_bar:*:*:*:*:*:odoo:*:* | |
References | () https://github.com/gmarczynski/odoo-web-progress/commit/3c867f1cf7447449c81b1aa24ebb1f7ae757489f - Patch | |
References | () https://github.com/luvsn/OdZoo/tree/main/exploits/web_progress - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-89 |
15 Dec 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-15 01:15
Updated : 2024-11-21 08:20
NVD link : CVE-2023-40954
Mitre link : CVE-2023-40954
CVE.ORG link : CVE-2023-40954
JSON object : View
Products Affected
gmarczynski
- dynamic_progress_bar
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')