CVE-2021-44460 — Improper Access Control in Community
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 35.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Description
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2021-44460: odoo - Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 1...↗2021