First published: Tue Dec 22 2020(Updated: )
Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
Credit: security@odoo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Odoo | >=11.0<=14.0 | |
Odoo Odoo | >=11.0<=14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15641 is a cross-site scripting (XSS) issue in the web module of Odoo Community and Odoo Enterprise versions 11.0 through 14.0.
CVE-2018-15641 allows remote authenticated internal users to inject arbitrary web script in the browser of a victim through crafted calendar event attributes.
CVE-2018-15641 has a severity rating of 5.4, which is classified as medium.
CVE-2018-15641 affects Odoo Community versions 11.0 through 14.0 and Odoo Enterprise versions 11.0 through 14.0.
To fix CVE-2018-15641 vulnerability, it is recommended to apply the necessary patches or updates provided by Odoo.