Cross-Site Scripting Vulnerability in Odoo by Odoo S.A.
CVE-2021-26947

6.5MEDIUM

Key Information:

Vendor

Odoo

Vendor
CVE Published:
25 April 2023

What is CVE-2021-26947?

This vulnerability allows remote attackers to execute arbitrary web scripts within the browser of the victim by crafting malicious links. Specifically, users of Odoo Community and Odoo Enterprise versions 15.0 and earlier are at risk, as these links can be used to inject harmful scripts, leading to potential unauthorized actions in the context of the user's session.

Affected Version(s)

Odoo Community 0 <= 15.0

Odoo Enterprise 0 <= 15.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nils Hamerlinck
Andreas Perhab
.