Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9cj-vm9v-xvj3

Опубликовано: 25 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.

EPSS

Процентиль: 63%
0.00456
Низкий

7.4 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.

CVSS3: 6.5
nvd
почти 3 года назад

Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.

CVSS3: 6.5
debian
почти 3 года назад

Improper access control in Odoo Community 13.0 and earlier and Odoo En ...

EPSS

Процентиль: 63%
0.00456
Низкий

7.4 High

CVSS3

Дефекты

CWE-284