Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45071

Опубликовано: 25 апр. 2023
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
odoofixed16.0.0+dfsg.1-1package

Примечания

  • https://github.com/odoo/odoo/issues/107697

  • 14.0 patch at https://github.com/odoo/odoo/commit/609b6503af97af5cf00ff497760f71cd71860c48

EPSS

Процентиль: 63%
0.00457
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

CVSS3: 6.1
nvd
почти 3 года назад

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

CVSS3: 5.3
github
почти 3 года назад

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

EPSS

Процентиль: 63%
0.00457
Низкий