id: CVE-2021-26947 info: name: Odoo <= 15.0 - Cross-Site Scripting author: ritikchaddha severity: medium description: | A cross-site scripting (XSS) vulnerability in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote attackers to inject arbitrary web scripts into the browser of a victim via a crafted link. This issue could lead to the execution of malicious scripts in the context of the user's browser session. impact: | Attackers can execute arbitrary scripts in victims' browsers, potentially stealing cookies, session tokens, or performing actions on behalf of the user. remediation: | Update to the latest version of Odoo where the vulnerability is fixed or apply security patches that sanitize user inputs properly. reference: - https://github.com/odoo/odoo/issues/107694 - https://www.debian.org/security/2023/dsa-5399 - https://nvd.nist.gov/vuln/detail/CVE-2021-26947 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cwe-id: CWE-79 cve-id: CVE-2021-26947 epss-score: 0.0141 epss-percentile: 0.69847 metadata: max-request: 3 verified: true vendor: odoo product: odoo tags: cve,cve2021,odoo,xss http: - method: GET path: - "{{BaseURL}}/web/login?error=" - "{{BaseURL}}/web/signup?error=" - "{{BaseURL}}/web/reset_password?error=" stop-at-first-match: true matchers: - type: dsl dsl: - 'contains_any(body, "", "", "")' - 'contains_any(body, "content=\"Odoo", "var odoo", "Odoo")' - 'contains(content_type, "text/html")' - 'status_code == 200' condition: and # digest: 4a0a00473045022100fe5945b84a5f2bd3b4bea1431377cda3668d2d9b9f2a321688d7e2ebc2ef217602201a6d777a63051ebde427755542dc43f45e1e129851e310ee0d4a9767db46051f:922c64590222798bb761d5b6d8e72950