Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q96-mp6q-xp49

Опубликовано: 25 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

EPSS

Процентиль: 61%
0.00421
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

CVSS3: 7.5
nvd
почти 3 года назад

Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.

CVSS3: 7.5
debian
почти 3 года назад

Improper access control in Odoo Community 15.0 and earlier and Odoo En ...

EPSS

Процентиль: 61%
0.00421
Низкий

7.5 High

CVSS3

Дефекты

CWE-284