Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5399-1 odoo security update
EUVD EUVD EUVD-2021-10288 Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: odoo

Published:

Updated: 2024-08-03T19:05:53.926Z

Reserved: 2021-12-27T06:19:18.867Z

Link: CVE-2021-23178

cve-icon Vulnrichment

Updated: 2024-08-03T19:05:53.926Z

cve-icon NVD

Status : Modified

Published: 2023-04-25T19:15:09.283

Modified: 2024-11-21T05:51:20.110

Link: CVE-2021-23178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.