5.3
CVE-2026-27463
- EPSS 0.25%
- Veröffentlicht 21.08.2026 20:16:34
- Zuletzt bearbeitet 09.09.2026 21:20:38
- Erkennungen
Combodo iTop: Version disclosure via login page logo
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCombodo
≫
Produkt
iTop
Version
< 3.2.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.167 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/Combodo/iTop/commit/d124f8ee58fa243193184ac2c55a561acdded356
https://github.com/Combodo/iTop/security/advisories/GHSA-hm9q-8jx3-f3v5