Improper Access Control in Odoo Community and Enterprise Products
CVE-2021-23178

7.5HIGH

Key Information:

Vendor

Odoo

Vendor
CVE Published:
25 April 2023

What is CVE-2021-23178?

A vulnerability in Odoo Community 15.0 and earlier, as well as Odoo Enterprise 15.0 and earlier, enables an attacker to exploit improper access control within the online payment processing system. By leveraging this flaw, an attacker could validate online payments using a tokenized payment method associated with another user, leading to unauthorized charges against the victim's payment method. This highlights a critical risk for businesses using Odoo for their online transactions and stresses the importance of proper access controls.

Affected Version(s)

Odoo Community 0 <= 15.0

Odoo Enterprise 0 <= 15.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Parth Gajjar
.