Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via crafted uploaded file names.
2023-04-25T19:15:09.963
2024-11-21T06:31:53.843
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | odoo | odoo | ≤ 15.0 | Yes |
Application | odoo | odoo | ≤ 15.0 | Yes |