VDB

CVE-2021-23203

CVE-2021-23203 PUBLISHED

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

EPSS 0.28% · 51.7th percentile

Risk Scores

EPSS Score
0.28%
51.7th percentile

Affected Products

VendorProductVersions
Bitnamiodoo14.0.0, 15.0.0
Bitnamiodoo14.0.0, 15.0.0

Timeline

  • Apr 25, 2023 CVE Published
  • Apr 26, 2023 EPSS Score
  • Jun 2, 2023 EPSS Score
  • Jul 9, 2023 EPSS Score
  • Aug 16, 2023 EPSS Score
  • Sep 22, 2023 EPSS Score
  • Oct 29, 2023 EPSS Score
  • Dec 5, 2023 EPSS Score
  • Jan 12, 2024 EPSS Score
  • Feb 18, 2024 EPSS Score
  • Mar 26, 2024 EPSS Score
  • May 2, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›