Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/odoo/odoo/issues/63701 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: odoo
Published: 2020-12-22T16:25:32
Updated: 2024-08-05T10:01:54.221Z
Reserved: 2018-08-21T00:00:00
Link: CVE-2018-15633
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-22T17:15:12.690
Modified: 2024-11-21T03:51:11.757
Link: CVE-2018-15633
Redhat
No data.