Description
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5399-1 | odoo security update |
EUVD |
EUVD-2021-10288 | Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that belongs to another user, causing the victim's payment method to be charged instead. |
References
History
Wed, 25 Feb 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Odoo odoo Community
Odoo odoo Enterprise |
|
| CPEs | cpe:2.3:a:odoo:odoo_community:*:*:*:*:*:*:*:* cpe:2.3:a:odoo:odoo_enterprise:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Odoo odoo Community
Odoo odoo Enterprise |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: odoo
Published:
Updated: 2024-08-03T19:05:53.926Z
Reserved: 2021-12-27T06:19:18.867Z
Link: CVE-2021-23178
Updated: 2024-08-03T19:05:53.926Z
Status : Modified
Published: 2023-04-25T19:15:09.283
Modified: 2024-11-21T05:51:20.110
Link: CVE-2021-23178
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD