Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, via crafted RPC requests.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: odoo

Published: 2023-04-25T18:33:39.776Z

Updated: 2024-08-04T04:25:16.836Z

Reserved: 2021-12-28T11:57:09.374Z

Link: CVE-2021-44465

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-04-25T19:15:09.727

Modified: 2024-07-15T02:15:03.533

Link: CVE-2021-44465

cve-icon Redhat

No data.