Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23178

Опубликовано: 25 апр. 2023
Источник: debian
EPSS Низкий

Описание

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
odoofixed16.0.0+dfsg.1-1package

Примечания

  • https://github.com/odoo/odoo/issues/107690

  • 14.0 patch at https://github.com/odoo/odoo/commit/5ac55247b576312ea4f1f274c94d955dd23335d1

EPSS

Процентиль: 50%
0.00268
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

CVSS3: 7.5
nvd
почти 3 года назад

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

CVSS3: 7.5
github
почти 3 года назад

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

EPSS

Процентиль: 50%
0.00268
Низкий