CVE Published: 25/04/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: odoo |
Vendor: Odoo |
Product: Odoo Community Status : PUBLISHED
CVE-2021-23203 Description
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N