Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-45071

Опубликовано: 25 апр. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 6.1
EPSS Низкий

Описание

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:*
Версия до 15.0 (включая)
cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:*
Версия до 15.0 (включая)

EPSS

Процентиль: 63%
0.00457
Низкий

5.3 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

CVSS3: 6.1
debian
почти 3 года назад

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and O ...

CVSS3: 5.3
github
почти 3 года назад

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.

EPSS

Процентиль: 63%
0.00457
Низкий

5.3 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79