High severity7.5NVD Advisory· Published Apr 25, 2023· Updated Jun 17, 2026
CVE-2021-23203
CVE-2021-23203
Description
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to download PDF reports for arbitrary documents, via crafted requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
814.0-15.0+ 1 more
- (no CPE)range: 14.0-15.0
- (no CPE)range: 14.0
Patches
Vulnerability mechanics
References
2- github.com/odoo/odoo/issues/107695nvdIssue TrackingPatchVendor Advisory
- www.debian.org/security/2023/dsa-5399nvd
News mentions
0No linked articles in our index yet.