VulnerabilityModified
CVE-2021-26263
Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
MEDIUM 6.1EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- odoo/odoo
- Source
- security@odoo.com
References
- https://github.com/odoo/odoo/issues/107693Issue Tracking, Patch, Vendor Advisory
- https://www.debian.org/security/2023/dsa-5399
- https://github.com/odoo/odoo/issues/107693Issue Tracking, Patch, Vendor Advisory
- https://www.debian.org/security/2023/dsa-5399
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.