Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
History

Tue, 24 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: odoo

Published: 2023-04-25T18:33:38.887Z

Updated: 2024-08-04T04:32:13.292Z

Reserved: 2021-12-28T11:57:09.384Z

Link: CVE-2021-44775

cve-icon Vulnrichment

Updated: 2024-08-04T04:32:13.292Z

cve-icon NVD

Status : Modified

Published: 2023-04-25T19:15:09.903

Modified: 2024-11-21T06:31:32.727

Link: CVE-2021-44775

cve-icon Redhat

No data.