Vulnerabilities > Odoo > Odoo > 12.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-12-22 | CVE-2018-15641 | Cross-site Scripting vulnerability in Odoo Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes. | 3.5 |
2020-12-22 | CVE-2018-15638 | Cross-site Scripting vulnerability in Odoo Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names. | 3.5 |
2020-12-22 | CVE-2018-15634 | Cross-site Scripting vulnerability in Odoo Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link. | 4.3 |
2019-04-09 | CVE-2018-15640 | Improper Privilege Management vulnerability in Odoo 10.0/11.0/12.0 Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request. | 9.0 |
2019-04-09 | CVE-2018-15635 | Cross-site Scripting vulnerability in Odoo Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of an internal user of the system by tricking them into inviting a follower on a document with a crafted name. | 4.3 |
2019-04-09 | CVE-2018-15631 | Unspecified vulnerability in Odoo Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the database, via a crafted RPC request. | 4.0 |