Saturday, September 26, 2026
1 change · master
Security fixes and vulnerability patches
Public job applications no longer update an existing contact just because the applicant used that contact's email address. This prevents someone submitting an application from changing an internal user's displayed name while still allowing recruitment records to match contacts by email.
Original PR description
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name.…
Issue: An unauthenticated visitor can submit a public job application with an internal user's email address and another applicant name. The submission then replaces the internal user's display name. Steps to reproduce: - Create an internal user and publish a job position. - Apply anonymously using the internal user's email and a different name. - Observe that the internal user's display name is replaced. Cause: `_inverse_partner_email()` handles a partner found from the submitted email as if it had already been explicitly linked to the applicant. It then synchronizes the untrusted applicant values onto that partner. Since public applications are created with elevated privileges, the email only match can modify an internal user's contact. https://github.com/odoo/odoo/blob/3b343f7b865bb1f57802f6df881ce4531d02c1ad/addons/hr_recruitment/models/hr_applicant.py#L228-L247 Solution: Use the applicant details only when the email lookup creates a new partner, and stop synchronization after an implicit email match. This allows applications to remain linked by email without letting the match modify an existing contact, while preserving synchronization for partners already explicitly linked to an applicant. opw-6472303 --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#286107 Forward-Port-Of: odoo/odoo#283546