CVE-2021-23178Improper Access Control in Odoo

Severity
7.5HIGHNVD
EPSS
0.4%
top 36.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25

Description

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5odoo/odoo_community15.0
CVEListV5odoo/odoo_enterprise15.0
debiandebian/odoo< odoo 14.0.0+dfsg.2-7+deb11u1 (bullseye)
Debianodoo/odoo< 14.0.0+dfsg.2-7+deb11u1
NVDodoo/odoo15.0

Patches

🔴Vulnerability Details

2
OSV
CVE-2021-23178: Improper access control in Odoo Community 152023-04-25
GHSA
GHSA-9q96-mp6q-xp49: Improper access control in Odoo Community 152023-04-25

💥Exploits & PoCs

1
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure2022-01-18

📋Vendor Advisories

1
Debian
CVE-2021-23178: odoo - Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 1...2021