A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Odoo | Odoo | * | 15.0 (including) | 
| Odoo | Ubuntu | kinetic | * | 
| Odoo | Ubuntu | lunar | * | 
| Odoo | Ubuntu | mantic | * | 
| Odoo | Ubuntu | oracular | * | 
| Odoo | Ubuntu | trusty | * | 
| Odoo | Ubuntu | xenial | * |