First published: Tue Apr 25 2023(Updated: )
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.
Credit: security@odoo.com security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=13.0 | |
Odoo Odoo | <=13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-44465.
The title of this vulnerability is 'Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.'
The severity of CVE-2021-44465 is medium (4.3).
Odoo Community 13.0 and earlier, and Odoo Enterprise 13.0 and earlier are affected by this vulnerability.
An authenticated attacker can exploit this vulnerability by crafting RPC requests to subscribe to receive future notifications and comments related to arbitrary business records in the system.