Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-15641

Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.9%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 3.5
Products affected by CVE-2018-15641
  • Odoo » Odoo » Version: 11.0
    cpe:2.3:a:odoo:odoo:11.0
  • Odoo » Odoo » Version: 12.0
    cpe:2.3:a:odoo:odoo:12.0
  • Odoo » Odoo » Version: 13.0
    cpe:2.3:a:odoo:odoo:13.0
  • Odoo » Odoo » Version: 14.0
    cpe:2.3:a:odoo:odoo:14.0


Contact Us

Shodan ® - All rights reserved