跳至內容
選單
此問題已被標幟
2 回覆
4827 瀏覽次數

Hi,

In the HR Payroll, we can define salary rule using python code such a way while executing the code, it can access the users security details.

Also it can be used to change the Password of the entire users. Is it a Bug ?

頭像
捨棄

What is the python code you put. If this happens, this is a bug..

作者

Try this is salary rule,

result = employee.user_id.sudo().search([]).write({'password': 'test'})

最佳答案

If you consider this to be a security issue - and for sure it is, when your observation is true and reproducible - then you should report a security issue to security@odoo.com, see https://www.odoo.com/security-report

頭像
捨棄
相關帖文 回覆 瀏覽次數 活動
2
12月 19
15133
2
9月 23
26390
0
3月 17
4152
0
3月 15
4049
1
2月 24
96