Filtered by vendor Combodo
Subscriptions
Filtered by product Itop
Subscriptions
Total
66 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-45808 | 1 Combodo | 1 Itop | 2025-02-06 | 4.1 Medium |
iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an out of scope Organization). Fixed in iTop 2.7.10, 3.0.4, 3.1.1, and 3.2.0. | ||||
CVE-2023-44396 | 1 Combodo | 1 Itop | 2025-02-06 | 6.8 Medium |
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1. | ||||
CVE-2023-43790 | 1 Combodo | 1 Itop | 2025-02-06 | 5.7 Medium |
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0. | ||||
CVE-2023-38511 | 1 Combodo | 1 Itop | 2025-02-06 | 5 Medium |
iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1. | ||||
CVE-2024-52000 | 1 Combodo | 1 Itop | 2025-01-07 | 6.1 Medium |
Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0 via systematic escaping of error messages when rendering on the page. All users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
CVE-2024-52001 | 1 Combodo | 1 Itop | 2025-01-07 | 4.3 Medium |
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
CVE-2024-52002 | 1 Combodo | 1 Itop | 2025-01-07 | 8.8 High |
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
CVE-2023-47489 | 1 Combodo | 1 Itop | 2024-11-21 | 7.8 High |
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components. | ||||
CVE-2023-47488 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page. | ||||
CVE-2023-34447 | 1 Combodo | 1 Itop | 2024-11-21 | 8.8 High |
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | ||||
CVE-2023-34446 | 1 Combodo | 1 Itop | 2024-11-21 | 8.8 High |
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | ||||
CVE-2022-31403 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php. | ||||
CVE-2022-31402 | 1 Combodo | 1 Itop | 2024-11-21 | 6.1 Medium |
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php. | ||||
CVE-2021-32776 | 1 Combodo | 1 Itop | 2024-11-21 | 6.8 Medium |
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0. | ||||
CVE-2021-32775 | 1 Combodo | 1 Itop | 2024-11-21 | 7.7 High |
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0. | ||||
CVE-2021-32664 | 1 Combodo | 1 Itop | 2024-11-21 | 8.1 High |
Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5. | ||||
CVE-2021-32663 | 1 Combodo | 1 Itop | 2024-11-21 | 8.7 High |
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later | ||||
CVE-2021-21407 | 1 Combodo | 1 Itop | 2024-11-21 | 8 High |
Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0. | ||||
CVE-2021-21406 | 1 Combodo | 1 Itop | 2024-11-21 | 5.8 Medium |
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0. | ||||
CVE-2020-4079 | 1 Combodo | 1 Itop | 2024-11-21 | 7.7 High |
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0. |