Quick acessQuick acess
NotificationNotification
LogsLogs
UsersUsers

Quick Access

Identity And Access Risks
Identity And Access Risks
Passed 50.0%
Vulnerable 50.0%
Financial And Invoicing Fraud
Financial And Invoicing Fraud
Passed 50.0%
Vulnerable 50.0%
Inventory And Procurement Abuse
Inventory And Procurement Abuse
Passed 50.0%
Vulnerable 50.0%
Integration And Api Abuse
Integration And Api Abuse
Passed 50.0%
Vulnerable 50.0%
Logging Monitoring And Configuration Gaps
Logging Monitoring And Configuration Gaps
Passed 50.0%
Vulnerable 50.0%
oosta
Execution plan
Do the following actions to make your oosta application more protected against fraud and cybersecurity issues in alignment with CrossClassify's SDK integration.
High
stop account takeover at login
Why: Over 54% of fraud losses in gaming stem from ATO attacks, often through credential stuffing and phishing.
Effort: LowETA: 20 minOwner: Security
High
enforce bot detection in gameplay
Why: Nearly 35% of gaming traffic is automated bots exploiting sign-ups, bonuses, or in-game economies.
Effort: LowETA: 30 minOwner: Security
Medium
protect players with biometrics
Why: Behavioral biometrics reduce fraudulent activity by 40%, while maintaining seamless gameplay for real users.
Effort: LowETA: 45 minOwner: Security
Identity And Access Risks

Identity And Access Risks

Multiple Admin Logins From New Countries Within Short Window
vulnerable

Your Odoo instance is vulnerable to admin account takeover. The timeline shows clusters of admin logins from new countries within minutes.

solution-badge
Reuse Of Expired Session Tokens By Different Ip Ranges
passed

All expired tokens revoked and unique per IP. No token reuse detected across IPs after expiry.

token_idip_rangeexpiry_statusreuse_count
tok_001192.168.1.0/24expired0
tok_00210.0.0.0/24expired0
tok_003172.16.0.0/24expired0
tok_004192.168.2.0/24expired0

Same Session Id Observed From Two Asns Within 10 Minutes
vulnerable

Your Odoo instance is vulnerable to session hijacking. Duplicate session IDs detected across ASNs within 10 minutes.

solution-badge
Sudden Login Switch To Different Browser Fingerprint
passed

Browser fingerprints consistent per user. No browser change patterns indicating session takeover.

user_idsession_idbrowser_fingerprintfingerprint_change
user_001sess_001fp_abc123none
user_002sess_002fp_def456none
user_003sess_003fp_ghi789none
user_004sess_004fp_jkl012none

Direct Role Change To Admin Without Approval
vulnerable

Your Odoo instance is vulnerable to privilege escalation. Unapproved role escalation detected on multiple days.

solution-badge
Post Escalation Sensitive Exports Or Mass Record Deletions
passed

No high-risk actions post escalation. All post-escalation activities are within normal parameters.

user_idescalation_datepost_escalation_actionsrisk_level
user_0012025-01-15view_reportslow
user_0022025-01-16update_settingslow
user_0032025-01-17view_dashboardlow
user_0042025-01-18manage_usersmedium

Greater Than 15 Failed Logins Then Success Within 15 Min
vulnerable

Your Odoo instance is vulnerable to credential stuffing. Brute-force bursts observed with >15 failed logins followed by success.

solution-badge
Many Failed Logins From Same Ip Or Device Pair
passed

IPs below threshold. No repeated failed logins from same device detected.

ip_addressdevice_idfailed_attemptsthreshold_status
192.168.1.100dev_0013below
192.168.1.101dev_0025below
192.168.1.102dev_0032below
192.168.1.103dev_0044below

New Token Used From Unknown Asn Plus Burst Volume
vulnerable

Your Odoo instance is vulnerable to API token abuse. Token spike detected from new ASN with burst volume.

solution-badge
Old Token Used After Revocation
passed

Revoked tokens blocked by API gateway. No stale tokens found active after revocation.

token_idrevocation_datelast_usagestatus
tok_rev_0012025-01-102025-01-09blocked
tok_rev_0022025-01-122025-01-11blocked
tok_rev_0032025-01-142025-01-13blocked
tok_rev_0042025-01-162025-01-15blocked
Financial And Invoicing Fraud

Financial And Invoicing Fraud

Bank Account Changed Less Than Or Equal 48 H Before Payment Run
vulnerable

Your Odoo instance is vulnerable to vendor bank tampering. Payment approved after recent bank change within 48 hours.

vendor_idbank_change_datepayment_datehours_betweenrisk_level
VEN0012025-01-152025-01-1748high
VEN0022025-01-162025-01-2096low
VEN0032025-01-182025-01-1924high
VEN0042025-01-202025-01-25120low
solution-badge
Bank Account Used Across Multiple Vendors
passed

Unique bank accounts per vendor. No shared bank accounts detected across multiple vendors.

Invoices With Same Amount Plus Minus 1 Percent Within 30 Days
vulnerable

Your Odoo instance is vulnerable to duplicate invoicing. Near-duplicate invoices found with same amounts within 30 days.

solution-badge
Invoices Without Corresponding Po Or Grn
passed

All invoices 3-way matched. No PO-bypass invoices detected.

invoice_idpo_idgrn_idmatch_status
INV001PO001GRN001matched
INV002PO002GRN002matched
INV003PO003GRN003matched
INV004PO004GRN004matched

High Refund Ratio By Same User Or Device
vulnerable

Your Odoo instance is vulnerable to refund abuse. One device dominates refunds with suspiciously high ratio.

solution-badge
Refunds Processed Outside Business Hours
passed

Refunds during working hours. No late-night refund bursts detected.

Frequent Approvals Between Same Pair
vulnerable

Your Odoo instance is vulnerable to employee-vendor collusion. Dense pairing network detected with frequent approvals between same pairs.

solution-badge
Reused Devices For Employee And Vendor Logins
passed

Distinct device IDs. No shared fingerprint detected between employees and vendors.

entity_identity_typedevice_idlogin_count
EMP001employeeDEV_EMP_00145
EMP002employeeDEV_EMP_00252
VEN001vendorDEV_VEN_00138
VEN002vendorDEV_VEN_00241

Many Small Pos Below Approval Threshold
vulnerable

Your Odoo instance is vulnerable to PO bypass. Spike near approval threshold detected with many small POs.

solution-badge
Similar Items Split Across Multiple Pos
passed

Unique line items per PO. No repeated SKUs detected in split POs.

po_idline_itemquantityunit_pricetotal_amount
PO001ITEM_A1050500
PO002ITEM_B5100500
PO003ITEM_C875600
PO004ITEM_D1240480
Inventory And Procurement Abuse

Inventory And Procurement Abuse

Repeated Negative Adjustments After Hours
vulnerable

Your Odoo instance is vulnerable to ghost stock adjustments. After-midnight spikes detected with repeated negative adjustments.

solution-badge
Adjustments Without Related Transfer Orders
passed

All linked to transfers. No unlinked stock entries detected.

adjustment_idtransfer_order_idadjustment_typelinkage_status
ADJ001TO001inventory_correctionlinked
ADJ002TO002damage_writeofflinked
ADJ003TO003cycle_countlinked
ADJ004TO004theft_losslinked

Sudden Margin Drops Greater Than 10 Percent On Sku Family
vulnerable

Your Odoo instance is vulnerable to price manipulation. Abrupt margin drops detected in Home category exceeding 10%.

solution-badge
Price Changes Without Approver Record
passed

All changes approved. No unauthorized change logs detected.

price_change_idsku_codeold_pricenew_priceapprover_idapproval_date
PC001SKU00110095MGR0012025-01-15
PC002SKU002200210MGR0022025-01-16
PC003SKU003150145MGR0012025-01-17
PC004SKU004300295MGR0032025-01-18

Multiple New Suppliers From Same Ip Or Device
vulnerable

Your Odoo instance is vulnerable to supplier onboarding fraud. Concentrated registrations detected from same IP/device.

solution-badge
Supplier Names With Pattern Similarity Greater Than 0 9
passed

Unique supplier strings. No synthetic duplicates detected.

supplier_idsupplier_namesimilarity_scoreduplicate_status
SUP001ABC Electronics Ltd0unique
SUP002XYZ Manufacturing Inc0unique
SUP003Global Supplies Co0unique
SUP004Tech Solutions LLC0unique

Grn Date Less Than Po Date
vulnerable

Your Odoo instance is vulnerable to GRN backdating. Negative intervals found with GRN dates before PO dates.

grn_idpo_idgrn_datepo_datedate_differencestatus
GRN001PO0012025-01-152025-01-141valid
GRN002PO0022025-01-162025-01-20-4backdated
GRN003PO0032025-01-172025-01-18-1backdated
GRN004PO0042025-01-182025-01-171valid
solution-badge
Grn Posted Far Before Invoice Receipt
passed

Reasonable posting intervals. No premature GRN entries detected.

Integration And Api Abuse

Integration And Api Abuse

Rising 401 Or 403 With High Volume
vulnerable

Your Odoo instance is vulnerable to brute-force attacks on /jsonrpc. Parallel error spike detected with high volume.

solution-badge
Sequential Login Requests From Scripted Ua
passed

UA patterns diverse. No identical scripted UAs detected.

request_iduser_agentrequest_patternsuspicious_score
REQ001Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36normal0.1
REQ002Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36normal0.1
REQ003Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36normal0.1
REQ004Mozilla/5.0 (iPhone; CPU iPhone OS 14_0 like Mac OS X) AppleWebKit/605.1.15normal0.1

Missing Hmac Signature In Requests
vulnerable

Your Odoo instance is vulnerable to webhook spoofing. Unverified payloads detected with missing HMAC signatures.

webhook_idsource_iphmac_signaturevalidation_statusrisk_level
WH001192.168.1.100valid_signature_abc123validlow
WH002192.168.1.101valid_signature_def456validlow
WH003192.168.1.102missinginvalidhigh
WH004192.168.1.103missinginvalidhigh
solution-badge
Replayed Webhook Requests Greater Than 1x
passed

0 replays detected. No replay attempts found.

Same Refresh Token From Two Geos
vulnerable

Your Odoo instance is vulnerable to OAuth token misuse. Cross-geo usage detected with same refresh token from different locations.

solution-badge
Refresh Token Used After Revocation
passed

Revoked tokens invalid. No old tokens found active after revocation.

token_idrevocation_datelast_usage_datestatus
rt_rev_0012025-01-102025-01-09revoked
rt_rev_0022025-01-122025-01-11revoked
rt_rev_0032025-01-142025-01-13revoked
rt_rev_0042025-01-162025-01-15revoked

High Frequency Read Api Calls No Carts
vulnerable

Your Odoo instance is vulnerable to rate scraping. Bot reads detected without corresponding cart actions.

solution-badge
Identical Payload Timing Intervals
passed

Varied timing detected. No perfect interval patterns found.

Logging Monitoring And Configuration Gaps

Logging Monitoring And Configuration Gaps

External Hits To Web Debug Equals
vulnerable

Your Odoo instance is vulnerable to debug mode exposure. Debug requests served to external IPs.

request_idsource_ipdebug_urlaccess_typerisk_level
REQ001192.168.1.100/web?debug=1internallow
REQ00210.0.0.50/web?debug=1internallow
REQ003203.0.113.45/web?debug=1externalhigh
REQ004198.51.100.123/web?debug=1externalhigh
solution-badge
Urls Leaking Database Names
passed

No db-name params detected. Database names not exposed in URLs.

No Create Write Delete Logs On Key Models
vulnerable

Your Odoo instance is vulnerable to audit trail deficiency. Missing audit logs detected on key models.

No Attachment Activity Logs
passed

Attachments logged. All file operations properly tracked.

attachment_idoperation_typeuser_idtimestamplog_status
ATT001createuser_0012025-01-15 10:30:00logged
ATT002readuser_0022025-01-15 11:15:00logged
ATT003updateuser_0032025-01-15 12:00:00logged
ATT004deleteuser_0012025-01-15 13:45:00logged

Known Cve Records Not Patched
vulnerable

Your Odoo instance is vulnerable to CVE exposure. Outdated modules detected with known vulnerabilities.

Outdated Dependency In Requirements Txt
passed

No deprecated packages detected. All dependencies are up to date.

package_namecurrent_versionlatest_versionstatus
requests2.31.02.31.0up_to_date
psycopg22.9.72.9.7up_to_date
lxml4.9.34.9.3up_to_date
pillow10.0.110.0.1up_to_date

Acls Granting Write Export Broadly
vulnerable

Your Odoo instance is vulnerable to over-permissive access rules. Wide write rights detected across critical models.

group_namemodel_nameperm_readperm_writeperm_createperm_unlinkrisk_level
base.group_userres.partnertruetruetruefalsemedium
base.group_useraccount.movetruetruetruetruehigh
base.group_userstock.movetruetruetruetruehigh
base.group_userres.userstruetruetruetruecritical
solution-badge
Group Inheritance Conflicts In Ir Model Access
passed

Clean inheritance detected. No nested conflicts found in access rules.

Tls Less Than 1 2 Or Weak Cipher Detected
vulnerable

Your Odoo instance is vulnerable to weak TLS configuration. Weak cipher suites and missing HSTS detected.

solution-badge
Mixed Http Https Content
passed

All secure requests detected. No mixed content found.

content_typehttp_counthttps_countmixed_content_status
static_assets0150secure
api_endpoints089secure
user_content0234secure
admin_panel045secure