VDB

CVE-2021-23203

CVE-2021-23203 PUBLISHED CVSS 7.5 HIGH

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

EPSS 0.88% · 56.1th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.88%
56.1th percentile

Affected Products

VendorProductVersions
Bitnamiodoo14.0.0, 15.0.0
Bitnamiodoo14.0.0, 15.0.0

Timeline

  • Apr 25, 2023 CVE Published
  • Apr 26, 2023 EPSS Score
  • Jun 2, 2023 EPSS Score
  • Jul 10, 2023 EPSS Score
  • Aug 16, 2023 EPSS Score
  • Sep 23, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
  • Dec 7, 2023 EPSS Score
  • Jan 13, 2024 EPSS Score
  • Feb 20, 2024 EPSS Score
  • Mar 28, 2024 EPSS Score
  • May 5, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›