Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: odoo

Published: 2023-04-25T18:33:33.360Z

Updated: 2024-08-04T04:25:16.420Z

Reserved: 2021-12-27T06:17:50.956Z

Link: CVE-2021-44460

cve-icon Vulnrichment

Updated: 2024-08-04T04:25:16.420Z

cve-icon NVD

Status : Modified

Published: 2023-04-25T19:15:09.600

Modified: 2024-11-21T06:31:01.170

Link: CVE-2021-44460

cve-icon Redhat

No data.