Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/odoo/odoo/issues/63704 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: odoo
Published: 2020-12-22T16:25:34
Updated: 2024-08-05T10:01:54.277Z
Reserved: 2018-08-21T00:00:00
Link: CVE-2018-15641
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-22T17:15:12.940
Modified: 2024-11-21T03:51:12.433
Link: CVE-2018-15641
Redhat
No data.