Cross-Site Scripting Vulnerability in Odoo Community and Enterprise Products
CVE-2018-15638

7.1HIGH

Key Information:

Vendor

Odoo

Vendor
CVE Published:
22 December 2020

What is CVE-2018-15638?

A Cross-Site Scripting (XSS) vulnerability exists in the mail module of Odoo Community and Enterprise versions 13.0 and earlier. This flaw can allow remote attackers to exploit the issue by crafting malicious channel names which, when triggered, inject arbitrary web scripts into the browsers of unsuspecting users. Successful exploitation could lead to data theft and unauthorized actions on behalf of users.

Affected Version(s)

Odoo Community <= 13.0

Odoo Enterprise <= 13.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Subash SN and Bharath Kumar (Appsecco)
Dipanshu Agrawal
.