First published: Tue Apr 25 2023(Updated: )
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
Credit: security@odoo.com security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | =14.0 | |
Odoo Odoo | =14.0 | |
Odoo Odoo | =15.0 | |
Odoo Odoo | =15.0 | |
debian/odoo | 14.0.0+dfsg.2-7+deb11u1 16.0.0+dfsg.2-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23203 is a vulnerability that allows remote attackers to download PDF reports for arbitrary documents in Odoo Community 14.0 through 15.0 and Odoo Enterprise 14.0 through 15.0.
CVE-2021-23203 has a severity value of 7.5 (high).
The CVE-2021-23203 vulnerability can be exploited by sending crafted requests to the reporting engine of Odoo, allowing remote attackers to download PDF reports for arbitrary documents.
Odoo Community versions 14.0 through 15.0 and Odoo Enterprise versions 14.0 through 15.0 are affected by CVE-2021-23203.
To fix CVE-2021-23203, you should update to the latest patched version of Odoo provided by the vendor.