CVE-2021-23203

HIGH

Odoo Community 14.0-15.0 and Odoo Enterprise 14.0-15.0 - Improper Access Control in Reporting Engine

Title source: llm
STIX 2.1

Description

Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.

References (2)

Core 2
Core References
Issue Tracking, Patch, Vendor Advisory
https://github.com/odoo/odoo/issues/107695

Scores

CVSS v3 7.5
EPSS 0.0088
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284 CWE-863
Status published
Products (2)
odoo/odoo 14.0 (2 CPE variants)
odoo/odoo 15.0 (2 CPE variants)
Published Apr 25, 2023
Tracked Since Feb 18, 2026