Record summary

CVE-2021-26947 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 15.0affected

Default status: unaffected

CVE ListThrough 15.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMOdoo <= 15.0 - Cross-Site ScriptingCVSS 6.1

A cross-site scripting (XSS) vulnerability in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote attackers to inject arbitrary web scripts into the browser of a victim via a crafted link. This issue could lead to the execution of malicious scripts in the context of the user's browser session.

Impact

Attackers can execute arbitrary scripts in victims' browsers, potentially stealing cookies, session tokens, or performing actions on behalf of the user.

Remediation

Update to the latest version of Odoo where the vulnerability is fixed or apply security patches that sanitize user inputs properly.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2021odooxss
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3