Combodo

Itop

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 10.11.2025 21:15:11
  • Zuletzt bearbeitet 21.11.2025 13:37:15

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which...

  • EPSS 0.05%
  • Veröffentlicht 10.11.2025 21:10:19
  • Zuletzt bearbeitet 21.11.2025 13:37:57

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callbac...

  • EPSS 0.04%
  • Veröffentlicht 10.11.2025 20:43:04
  • Zuletzt bearbeitet 21.11.2025 13:38:44

Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't b...

  • EPSS 0.05%
  • Veröffentlicht 10.11.2025 20:35:34
  • Zuletzt bearbeitet 21.11.2025 21:12:11

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered HTML content.

  • EPSS 0.04%
  • Veröffentlicht 10.11.2025 20:33:48
  • Zuletzt bearbeitet 21.11.2025 21:12:36

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0.

  • EPSS 0.05%
  • Veröffentlicht 10.11.2025 19:20:24
  • Zuletzt bearbeitet 21.11.2025 21:13:18

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var responsible for the attack.

  • EPSS 0.05%
  • Veröffentlicht 10.11.2025 19:15:57
  • Zuletzt bearbeitet 21.11.2025 21:13:48

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Versions 2.7.13 and 3.2.2 protect rendered HTML content.

  • EPSS 0.11%
  • Veröffentlicht 10.11.2025 18:38:40
  • Zuletzt bearbeitet 21.11.2025 21:15:31

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config ...

  • EPSS 0.06%
  • Veröffentlicht 14.05.2025 15:11:45
  • Zuletzt bearbeitet 05.08.2025 20:49:48

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

  • EPSS 0.08%
  • Veröffentlicht 14.05.2025 15:05:28
  • Zuletzt bearbeitet 01.08.2025 18:38:35

iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by che...