Bỏ qua để đến Nội dung
Odoo Menu
  • Đăng nhập
  • Dùng thử miễn phí
  • Ứng dụng
    Tài chính
    • Kế toán
    • Hóa đơn
    • Chi phí
    • Bảng tính (BI)
    • Tài liệu
    • Ký tên
    Bán hàng
    • CRM
    • Bán hàng
    • POS Cửa hàng
    • POS Nhà hàng
    • Đăng ký
    • Cho thuê
    Trang web
    • Trình tạo trang web
    • Thương mại điện tử
    • Blog
    • Diễn đàn
    • Trò chuyện trực tiếp
    • Học trực tuyến
    Chuỗi cung ứng
    • Tồn kho
    • Sản xuất
    • PLM
    • Mua hàng
    • Bảo dưỡng
    • Chất lượng
    Nhân sự
    • Nhân viên
    • Tuyển dụng
    • Ngày nghỉ
    • Đánh giá
    • Giới thiệu
    • Đội xe
    Marketing
    • Marketing trên MXH
    • Marketing qua email
    • Marketing qua SMS
    • Sự kiện
    • Tự động hóa Marketing
    • Khảo sát
    Dịch vụ
    • Dự án
    • Bảng chấm công
    • Dịch vụ hiện trường
    • Hỗ trợ
    • Kế hoạch
    • Lịch hẹn
    Năng suất
    • Thảo luận
    • Trí tuệ nhân tạo (AI)
    • IoT
    • VoIP
    • Kiến thức
    • WhatsApp
    Ứng dụng của bên thứ ba Studio Odoo Nền tảng Đám mây Odoo
  • Ngành
    Bán lẻ
    • Nhà sách
    • Cửa hàng quần áo
    • Cửa hàng nội thất
    • Cửa hàng tạp hóa
    • Cửa hàng đồ kim khí
    • Cửa hàng đồ chơi
    Ẩm thực & Dịch vụ lưu trú
    • Bar và quán rượu
    • Nhà hàng
    • Đồ ăn nhanh
    • Guest house
    • Nhà phân phối đồ uống
    • Khách sạn
    Bất động sản
    • Công ty môi giới bất động sản
    • Công ty kiến trúc
    • Xây dựng
    • Quản lý bất động sản
    • Làm vườn
    • Hiệp hội chủ sở hữu bất động sản
    Tư vấn
    • Công ty kế toán
    • Đối tác Odoo
    • Công ty marketing
    • Công ty luật
    • Tuyển dụng
    • Thanh tra & chứng nhận
    Sản xuất
    • Dệt may
    • Kim loại
    • Nội thất
    • Ẩm thực
    • Nhà máy bia
    • Quà tặng doanh nghiệp
    Sức khoẻ & fitness
    • CLB thể thao
    • Cửa hàng kính mắt
    • Trung tâm fitness
    • Chuyên gia chăm sóc sức khỏe
    • Hiệu thuốc
    • Tiệm làm tóc
    Thương mại
    • Dịch vụ sửa chữa
    • Phần cứng CNTT & Hỗ trợ
    • Hệ thống năng lượng mặt trời
    • Công ty sản xuất giày
    • Dịch vụ vệ sinh
    • Dịch vụ HVAC
    Khác
    • Tổ chức phi lợi nhuận
    • Cơ quan môi trường
    • Cho thuê biển quảng cáo
    • Nhiếp ảnh
    • Cho thuê xe đạp
    • Đại lý phần mềm
    Xem tất cả ngành
  • Cộng đồng
    Học tập
    • Khóa học
    • Tài liệu
    • Chứng chỉ
    • Đào tạo
    • Blog
    • Podcast
    Thúc đẩy đào tạo
    • Chương trình đào tạo
    • Trò chơi kinh doanh Scale Up!
    • Tham quan Odoo
    Nhận phần mềm
    • Tải xuống
    • So sánh các phiên bản
    • Phiên bản
    Hợp tác
    • Github
    • Diễn đàn
    • Sự kiện
    • Dịch thuật
    • Trở thành đối tác
    • Dịch vụ dành cho Đối tác
    • Đăng ký công ty kế toán của bạn
    • Affiliate Program
    Nhận dịch vụ
    • Tìm đối tác
    • Tìm kế toán
    • Gặp chuyên gia hỗ trợ
    • Dịch vụ Triển khai
    • Khách hàng tham khảo
    • Hỗ trợ
    • Nâng cấp
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Nhận một buổi demo
  • Bảng giá
  • Trợ giúp

Responsible Disclosure Policy

For Odoo security vulnerabilities. We take the safety of Odoo systems seriously, and we welcome reports from users and contributors who help us keep them that way.

What NOT to report Security Hall of Fame

The safety of Odoo systems is very important to us not only because we use Odoo internally, but also because we consider security problems with the highest priority. We do our best every day to protect Odoo users from known security threats, and we welcome all reports of security vulnerabilities discovered by our users and contributors.

We are committed to handling vulnerability reports with the greatest attention, provided that the following rules are respected.

Top Researchers

Nils Hamerlinck (Trobz)
Colin Newell
IBS Group
See the full Hall of Fame

Reporting an issue

Please share the details of your security vulnerability privately by emailing our Security Team at security@odoo.com. Include as much information as possible: detailed steps to reproduce the problem, the versions affected, expected vs. actual results, and anything else that helps us react faster. We prefer text-based bug descriptions with a proof-of-concept over long videos.

Reporting vulnerabilities via third-party websites is not acceptable, as it breaches the terms of our policy. If you are looking for a third-party reward, we may forward the list of CVE IDs assigned to you, so they can verify your rewards — but the issues have to be reported to us directly.

Heads up: Most reports we receive have little to no real impact and get rejected. Before reaching out, put together a proof-of-concept attack and take a critical look at what's really at risk. Also, please review the non-qualifying list below.

Our GPG key

4096R/8E877D2F

Fingerprint: 9083 DE46 54A7 8DE3 CFAD D880 0B9E A35A 8E87 7D2F

Download key (keys.openpgp.org) Download key (mirror)

Incident response procedure

  1. You privately share the vulnerability details with our Security Team.
  2. We acknowledge your submission and verify the vulnerability. Our first answer generally comes within 48h.
  3. If valid and in scope, we request a CVE ID and share it with you as soon as it's assigned.
  4. We work on a correction in collaboration with you.
  5. We write a detailed Security Advisory covering the issue, its impact, workarounds and solution, and ask you to review it.
  6. We privately broadcast the advisory and correction to stakeholders and Odoo Enterprise customers.
  7. We give stakeholders and customers a reasonable delay to apply the fix before disclosing publicly (e.g. 2–3 weeks).
  8. We disclose and broadcast the advisory and correction on our public channels.

Rules of engagement

We ask you to always:

  • Test exclusively on your own deployments, demo.odoo.com, or your own Odoo Cloud databases
  • Never access or modify data that isn't yours
  • Never attempt denial-of-service attacks or compromise services that aren't yours
  • Avoid automated scanners unless throttled to under 5 req/s (ideally 1 req/s) and rule-compliant
  • Use AI responsibly, always review results, never allow automatic submissions
  • Never use social engineering, phishing, or physical attacks without our prior consent
  • Keep vulnerabilities private until we've agreed on disclosure

In return, we commit to:

  • Not initiate legal action against you if you followed the rules
  • Process your report and respond as quickly as possible
  • Provide a fix as soon as possible
  • Work diligently with stakeholders to help restore system safety
  • Keep your identity private, unless you want to be credited

What to report

Qualifying vulnerabilities — do report!

  • SQL injection vectors in public API methods
  • XSS vulnerabilities working in supported browsers
  • Broken authentication or session management allowing unauthorized access
  • Broken sandboxing of customizations, allowing code execution or system access

Non-qualifying vulnerabilities — do not report

  • Unsupported Browser XSS: Cross-Site Scripting (XSS) that only works in outdated or unsupported browsers, or requires relaxed browser security settings.
  • Self-XSS: Attacks where a user must be tricked into actively copying and pasting malicious code into their own browser console.
  • Administrator "XSS": Script injection or XSS via file uploads (SVG, HTML, JS) by users with Administrator privileges. Administrators are effectively webmasters; security restrictions do not apply to them by design.
  • Rate-limiting / Brute-forcing: Lack of rate limiting or brute-force protections on components working as designed (e.g., password authentication, password resets).
  • User Enumeration: The ability to verify whether a username exists. This carries minimal risk and cannot be prevented without deteriorating the legitimate user experience.
  • File Path Disclosure: Revealing file paths on the server, which does not pose a significant risk or enable further attacks.
  • Clickjacking & Social Engineering: Phishing or clickjacking attacks that rely on social engineering to trick users, while the system itself is functioning as intended.
  • Tabnapping: Phishing attacks conducted by manipulating or navigating other browser tabs.
  • Logout CSRF: Forcing a user to log out via Cross-Site Request Forgery. This is not considered a plausible attack unless combined with Login CSRF, and is practically unpreventable.
  • Open Redirectors: These are merely one phishing vector among many (see our detailed explanation).
  • Reflected File Downloads: An attack technique requiring social engineering that is rarely practical in real-world scenarios.
  • CSV/XLSX Injection: Formula injection issues that require the victim to explicitly ignore and bypass security warnings in modern spreadsheet software (like Excel).
  • Referer Leaks: Leaking sensitive tokens via the Referer header to social media links, ads, or analytics requests. These are highly unlikely to be clicked or exploited within their validity period by mainstream providers.
  • Physical & Social Attacks: Any attack relying on physical access to a device or social engineering techniques against users or staff.
  • Non-permanent DoS/DDoS: Denial of Service attacks that exhaust resources (CPU, network, memory) simply by sending a sustained, massive stream of requests or packets.
  • Password Policies: Weaknesses related to password length, formats, character classes, or expiration policies.
  • Email Verification Bypass: Missing or partial verification of email addresses, or methods to circumvent the verification process.
  • Public Information Disclosure: Revealing public data or information with no significant risk (e.g., directory listings on our public download archives are a required feature).
  • Spam-fighting Policies: Missing or misconfigured DKIM, SPF, or DMARC records.
  • HSTS Configuration: The absence of HTTP Strict Transport Security (HSTS) headers, HSTS preloading, or HSTS policies.
  • Weak SSL/Ciphers: Specifics of weak ciphers or SSL deployments, as long as our benchmark remains an 'A' grade on SSLLabs with maximum compatibility for users.
  • SSRF Attacks: Server-Side Request Forgery, unless it allows access to special protocol handlers (e.g., file://) or successfully bypasses access controls on Odoo Cloud Hosting.
  • Default Access Control Rules: Issues stemming from the default configuration of access control rules (like ACLs and record rules). Please report these as regular bug reports instead.
  • Prior Account Takeover Required: Attack scenarios that require the attacker to have already compromised the user's Odoo account or email account. Please open regular bug reports for these.

If you have any doubt, please ask.

Reward

If you report a new security issue confirmed to be critical, we'll publicly thank you by adding your name to the Odoo Security Hall of Fame below.

Security Hall of Fame

We're extremely grateful to the security researchers who've worked with us to make Odoo and the Odoo Cloud platforms safer.

85
Researchers
14
Years running
14
Repeat contributors

Recent Entries

khanhdlq
First report
Youssef Badaoui
First report
David Vidal
First report
Jayendra Yogi (ghostvirus)
First report
Kristjan Tehu
First report

Security Expert Security Analyst Security Enthusiast

Nils Hamerlinck (Trobz) ×8 Colin Newell ×3 IBS Group ×4 Swapnesh Shah ×2 Naglis Jonaitis ×4 Ondřej Kuzník ×3 khanhdlq Elliot Ward ×2 lebr0nli (Alan Li) Alexandre Moens ×2 iamsushi ×2 Florent Mirieu de Labarre ×2 Youssef Badaoui David Vidal Jayendra Yogi (ghostvirus) Kristjan Tehu Shankar Biswas Bhavin Fadadu Rafi Shapiro Niyas Raphy Rifat Al Jubayer Alexandre Díaz ×2 Andreas Perhab (WT-IO-IT GmbH) Iago Ruiz Johannes Moritz (Cure53) Moez Hemani Parth Gajjar Ranjit Pahan Theodoros Malachias Abhiram V Alessandro Innocenti Christopher Riis Bubeck Eriksen Damien LESCOS Kennedy Sanchez Loc Truong Raspina Net Pars Group Santosh Kumar Sha Agustín Ezequiel Maio Aitor Fuentes (kr0no) Anıl Yüksel Bharath Kumar (Appsecco) ×2 Dipanshu Agrawal Emre Övünç Holger Brunn (Hunki Enterprises BV) Lauri Vakkala (Silverskin) Nathanael ROTA (Capgemini) P. Valov (SoCyber) Subash SN (Appsecco) ×2 Tomas Canzoniero Yenthe Van Ginneken ×2 Adan Álvarez (A2secure) Benoît Chenal (Excellium-services) Carlos Daudén (Tecnativa S.L.) Erwin van der Ploeg (Odoo Experts) Hugo Rodrigues Mehmet Tuncer Moises Lopez Stéphane Bidoul (ACSONE) "Ayrx" via SSD Adel Nettar (Sysdream) Andrew Grasso (Logic Supply) Azizul Hakim Corben Leo Juba Baghdad Prakash Dhatti Romain E Silva (Sysdream) Wolfgang Taferner (WT-IO-IT GmbH) Cameron Dawe Mohammad Alhashash Nagaraju Repala Vibhuti Ranjan Vidyarshy Nath Xavier Alt Dipak Kumar Das Leonardo Pistone (Camptocamp France) Mohamed Khaled Fathy Muhammed Gamal Fahmy Ondřej Kuzník & Craig Gowing (credativ Ltd) ONESTEiN / Glasswall Openinside Co. Paul Catinean Sven Schleier (KPMG Management Consulting, SG) "diesenfranz" Daniel Lawson Bastian Ike Vo Minh Thu

Special thanks

Aaron Devaney, Abhishek Venkat, Ahsan Khan, Ameya Darshan, Caleb Kinney, Cédric Krier, Christophe Hanon, Deepali Malekar, Fazal Ur Rahman, Flo van der Vlist, Huzaifa Jawaid, Ismail Tasdelen, Ivan Yelizariev, Jairo Llopis, Khan Janny, Leonardo "LeartS" Donelli, Mohammed Israil, Mohamed Karara, Niyas Raphy, Riccardo Ancarani, Saddam Maniyar, Sameer Phad, Sébastien Versailles, "St00rm N00b", Suyog Palav, Tarun Manhor-Abhaychandra Chede, Tayler Porter, Ye Yint Min Thu Htut, Ziaur Rashid.

Cộng đồng
  • Khóa học
  • Tài liệu
  • Diễn đàn
Open source
  • Tải xuống
  • Github
  • Runbot
  • Dịch thuật
Dịch vụ
  • Lưu trữ Odoo.sh
  • Hỗ trợ
  • Nâng cấp
  • Phát triển tùy chỉnh
  • Đào tạo
  • Tìm kế toán
  • Tìm đối tác
  • Trở thành đối tác
Giới thiệu công ty
  • Công ty của chúng tôi
  • Tài sản thương hiệu
  • Liên hệ
  • Việc làm
  • Sự kiện
  • Podcast
  • Blog
  • Khách hàng
  • Pháp lý • Riêng tư
  • Bảo mật
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) Português română русский язык Slovenský jazyk Slovenščina Español (América Latina) Español Svenska ภาษาไทย Türkçe українська Tiếng Việt

Odoo là bộ ứng dụng kinh doanh có open source đáp ứng tất cả các nhu cầu của công ty bạn: CRM, thương mại điện tử, kế toán, tồn kho, POS, quản lý dự án, v.v.

Định hướng giá trị riêng biệt của Odoo là tích hợp hoàn toàn và dễ dàng sử dụng.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now