Odoo < 16.2022.12.24 Cross-Site Scripting

medium Web App Scanning Plugin ID 113977

Synopsis

Odoo < 16.2022.12.24 Cross-Site Scripting

Description

Odoo in version prior to 16.2022.12.24 is vulnerable to Cross-Site Scripting due to a lack of filtering and incorrect content-type through an API handler.

Solution

Upgrade to Odoo version 16.2022.12.24 or later.

See Also

https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else/

Plugin Details

Severity: Medium

ID: 113977

Type: remote

Published: 7/24/2023

Updated: 7/24/2023

Scan Template: basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:odoo:odoo:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/26/2023

Vulnerability Publication Date: 4/26/2023

Reference Information

CVE: CVE-2023-1434