CVE-2021-44461: XSS
Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control the contents of accounting journal entries to inject arbitrary web script in the browser of a victim.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44461?
CVE-2021-44461 is a cross-site scripting (XSS) vulnerability in the Accounting app of Odoo Enterprise 13.0 through 15.0.
How does CVE-2021-44461 affect Odoo Enterprise?
CVE-2021-44461 allows remote attackers to inject arbitrary web script in the browser of a victim by controlling the contents of accounting journal entries.
What is the severity of CVE-2021-44461?
The severity of CVE-2021-44461 is medium, with a CVSS score of 6.1.
How can I fix CVE-2021-44461 in Odoo Enterprise?
To fix CVE-2021-44461, update Odoo Enterprise to a version higher than 15.0 or apply the appropriate patch provided by the vendor.
Where can I find more information about CVE-2021-44461?
You can find more information about CVE-2021-44461 on the GitHub issue: https://github.com/odoo/odoo/issues/107686