CVE-2021-23176: Medium severity odoo vulnerability
Improper access control in reporting engine of l10nfrfec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23176?
CVE-2021-23176 is a vulnerability that allows remote authenticated users to extract accounting information via crafted RPC packets in the reporting engine of the l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
What is the severity of CVE-2021-23176?
The severity of CVE-2021-23176 is medium (6.5).
How does CVE-2021-23176 affect Odoo?
CVE-2021-23176 affects Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier.
How can remote authenticated users exploit CVE-2021-23176?
Remote authenticated users can exploit CVE-2021-23176 by sending crafted RPC packets to the reporting engine of the l10n_fr_fec module in Odoo.
Are there any fixes available for CVE-2021-23176?
Yes, there are fixes available. Please refer to the provided references for more information.