Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.
References
History

Mon, 03 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: odoo

Published:

Updated: 2025-02-03T17:16:04.447Z

Reserved: 2021-12-28T11:57:09.374Z

Link: CVE-2021-44465

cve-icon Vulnrichment

Updated: 2024-08-04T04:25:16.836Z

cve-icon NVD

Status : Modified

Published: 2023-04-25T19:15:09.727

Modified: 2025-02-03T18:15:27.513

Link: CVE-2021-44465

cve-icon Redhat

No data.