CVE-2018-15641 describes a cross-site scripting (XSS) vulnerability affecting Odoo Community and Enterprise versions 11.0 through 14.0. This flaw allows authenticated internal users to inject malicious web scripts into a victim's browser through crafted calendar event attributes. The vulnerability is rated Medium severity (CVSS 5.4), indicating it can be exploited over the network with low attack complexity, requiring user interaction and low privileges. A successful exploit could lead to limited confidentiality and integrity impacts. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion or media coverage, suggesting it is not widely recognized or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, <= 14.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:*:*:*:*:community:*:*:* | ||
>= 11.0, <= 14.0CPE matchmatch criteria | cpe:2.3:a:odoo:odoo:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.