First published: Tue Dec 22 2020(Updated: )
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | <=11.0 | |
Odoo Odoo | <=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this XSS issue is CVE-2018-15633.
The severity of CVE-2018-15633 is high with a severity value of 6.1.
The software versions affected by CVE-2018-15633 are Odoo Community 11.0 and earlier, and Odoo Enterprise 11.0 and earlier.
Remote attackers can exploit CVE-2018-15633 by injecting arbitrary web script in the browser of a victim via crafted attachment filenames.
Yes, a fix is available for CVE-2018-15633. It is recommended to update to a version that has addressed this vulnerability.