CVE-2021-26947
Odoo <= 15.0 - Cross-Site Scripting
Record summary
CVE-2021-26947 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Odoo CommunityBrowse Odoo / Odoo CommunityDefault status: unaffected | CVE List | Through 15.0 | affected |
Odoo EnterpriseBrowse Odoo / Odoo EnterpriseDefault status: unaffected | CVE List | Through 15.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMOdoo <= 15.0 - Cross-Site ScriptingCVSS 6.1
A cross-site scripting (XSS) vulnerability in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote attackers to inject arbitrary web scripts into the browser of a victim via a crafted link. This issue could lead to the execution of malicious scripts in the context of the user's browser session.
Impact
Attackers can execute arbitrary scripts in victims' browsers, potentially stealing cookies, session tokens, or performing actions on behalf of the user.
Remediation
Update to the latest version of Odoo where the vulnerability is fixed or apply security patches that sanitize user inputs properly.
Source: ProjectDiscovery