First published: Tue Apr 25 2023(Updated: )
Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.
Credit: security@odoo.com security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=15.0 | |
Odoo Odoo | <=15.0 | |
debian/odoo | 14.0.0+dfsg.2-7+deb11u1 16.0.0+dfsg.2-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23176 is a vulnerability that allows remote authenticated users to extract accounting information via crafted RPC packets in the reporting engine of the l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
The severity of CVE-2021-23176 is medium (6.5).
CVE-2021-23176 affects Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
Remote authenticated users can exploit CVE-2021-23176 by sending crafted RPC packets to the reporting engine of the l10n_fr_fec module in Odoo.
Yes, there are fixes available. Please refer to the provided references for more information.