Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-31297 Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC requests.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: odoo

Published:

Updated: 2024-08-04T04:25:16.420Z

Reserved: 2021-12-27T06:17:50.956Z

Link: CVE-2021-44460

cve-icon Vulnrichment

Updated: 2024-08-04T04:25:16.420Z

cve-icon NVD

Status : Modified

Published: 2023-04-25T19:15:09.600

Modified: 2024-11-21T06:31:01.170

Link: CVE-2021-44460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.