id: odoo-database-manager info: name: Odoo Database Manager Panel - Detect author: __Fazal,R3dg33k severity: critical description: Odoo database manager was discovered and allows access to databases. reference: - https://www.odoo.com/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cwe-id: CWE-200 tags: panel,odoo requests: - method: GET path: - '{{BaseURL}}/web/database/manager' matchers-condition: and matchers: - type: status status: - 200 - type: word words: - "Odoo" - "{ action: 'database_manager' }" condition: and # Enhanced by mp on 2022/07/15