Improper Access Control in Odoo Community and Enterprise Products
CVE-2021-23178
What is CVE-2021-23178?
A vulnerability in Odoo Community 15.0 and earlier, as well as Odoo Enterprise 15.0 and earlier, enables an attacker to exploit improper access control within the online payment processing system. By leveraging this flaw, an attacker could validate online payments using a tokenized payment method associated with another user, leading to unauthorized charges against the victim's payment method. This highlights a critical risk for businesses using Odoo for their online transactions and stresses the importance of proper access controls.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Odoo Community 0 <= 15.0
Odoo Enterprise 0 <= 15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
