Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5399-1 | odoo security update |
EUVD |
EUVD-2021-10286 | Improper access control in reporting engine of l10n_fr_fec module in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to extract accounting information via crafted RPC packets. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: odoo
Published:
Updated: 2024-08-03T19:05:54.464Z
Reserved: 2021-12-27T06:14:42.052Z
Link: CVE-2021-23176
Updated: 2024-08-03T19:05:54.464Z
Status : Modified
Published: 2023-04-25T19:15:09.220
Modified: 2024-11-21T05:51:19.833
Link: CVE-2021-23176
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD