5
CVE-2025-24021
- EPSS 0.22%
- Veröffentlicht 14.05.2025 14:48:42
- Zuletzt bearbeitet 22.08.2025 21:15:30
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
iTop doesn't have mass assignment of fields in the portal form
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.128 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/Combodo/iTop/security/advisories/GHSA-c8hm-h9gv-8jpj
https://github.com/Combodo/iTop/commit/44290db312901fc5918cc537c74561487fb3713b