CVE-2018-15635Cross-site Scripting in Community

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 13

Description

Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5odoo/odoo_communityunspecified12.0
CVEListV5odoo/odoo_enterpriseunspecified12.0
NVDodoo/odoo12.0
debiandebian/odoo

🔴Vulnerability Details

1
GHSA
GHSA-h8hp-ch7h-x355: Cross-site scripting vulnerability in the Discuss App of Odoo Community 122022-05-13

📋Vendor Advisories

1
Debian
CVE-2018-15635: odoo - Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and...2018