CVE-2018-15634: XSS
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-15634?
CVE-2018-15634 is a cross-site scripting (XSS) vulnerability in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier.
How does CVE-2018-15634 affect me?
CVE-2018-15634 allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link, potentially leading to information theft or unauthorized actions on the affected system.
What is the severity of CVE-2018-15634?
CVE-2018-15634 has a severity ranking of 6.1 (high).
How can I fix CVE-2018-15634?
To fix CVE-2018-15634, it is recommended to update to a version of Odoo Community or Odoo Enterprise that is later than 14.0.
Where can I find more information about CVE-2018-15634?
You can find more information about CVE-2018-15634 in the official GitHub issue for Odoo: https://github.com/odoo/odoo/issues/63702