Merge pull request #7389 from ruben-condor/improve_cve-2023-1434-template
Updated CVE-2023-1434.yaml templatepatch-1
commit
68d776d90a
|
@ -4,6 +4,8 @@ info:
|
|||
name: Odoo - Cross-Site Scripting
|
||||
author: DhiyaneshDK
|
||||
severity: medium
|
||||
description: |
|
||||
Odoo is a business suite that has features for many business-critical areas, such as e-commerce, billing, or CRM. Versions before the 16.0 release are vulnerable to CVE-2023-1434 and is caused by an incorrect content type being set on an API endpoint.
|
||||
reference:
|
||||
- https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else
|
||||
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1434
|
||||
|
|
Loading…
Reference in New Issue