Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5399-1 | odoo security update |
EUVD |
EUVD-2021-13080 | Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Odoo odoo Community
Odoo odoo Enterprise |
|
| CPEs | cpe:2.3:a:odoo:odoo_community:14.0:*:*:*:*:*:*:* cpe:2.3:a:odoo:odoo_enterprise:14.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Odoo odoo Community
Odoo odoo Enterprise |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: odoo
Published:
Updated: 2024-08-03T20:19:20.148Z
Reserved: 2021-07-20T14:28:12.183Z
Link: CVE-2021-26263
Updated: 2024-08-03T20:19:20.148Z
Status : Modified
Published: 2023-04-25T19:15:09.470
Modified: 2024-11-21T05:56:00.197
Link: CVE-2021-26263
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD