CVE-2021-26263

NameCVE-2021-26263
DescriptionCross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackers to inject arbitrary web script in the browser of a victim, by posting crafted contents.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5399-1
Debian Bugs1035953

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
odoo (PTS)bullseye (security), bullseye14.0.0+dfsg.2-7+deb11u1fixed
sid16.0.0+dfsg.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
odoosourcebullseye14.0.0+dfsg.2-7+deb11u1DSA-5399-1
odoosource(unstable)16.0.0+dfsg.1-11035953

Notes

https://github.com/odoo/odoo/issues/107693
14.0 patch at https://github.com/odoo/odoo/commit/ff1db4a6aea522cf3dfc80ca88e64ffecfb5e07c

Search for package or bug name: Reporting problems