Merge pull request #7389 from ruben-condor/improve_cve-2023-1434-template

Updated CVE-2023-1434.yaml template
patch-1
pussycat0x 2023-06-12 19:28:04 +05:30 committed by GitHub
commit 68d776d90a
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 0 deletions

View File

@ -4,6 +4,8 @@ info:
name: Odoo - Cross-Site Scripting name: Odoo - Cross-Site Scripting
author: DhiyaneshDK author: DhiyaneshDK
severity: medium severity: medium
description: |
Odoo is a business suite that has features for many business-critical areas, such as e-commerce, billing, or CRM. Versions before the 16.0 release are vulnerable to CVE-2023-1434 and is caused by an incorrect content type being set on an API endpoint.
reference: reference:
- https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else - https://www.sonarsource.com/blog/odoo-get-your-content-type-right-or-else
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1434 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1434