CVE-2024-51995
- EPSS 0.11%
- Veröffentlicht 07.11.2024 18:15:18
- Zuletzt bearbeitet 27.03.2025 18:29:13
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in...
CVE-2024-51994
- EPSS 0.35%
- Veröffentlicht 07.11.2024 18:15:18
- Zuletzt bearbeitet 04.04.2025 20:03:59
Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (XSS) vulnerability. This issue has been addressed in version 3.2.0 and ...
CVE-2024-51993
- EPSS 0.02%
- Veröffentlicht 07.11.2024 18:15:18
- Zuletzt bearbeitet 04.04.2025 20:05:22
Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users un...
CVE-2024-51740
- EPSS 0.13%
- Veröffentlicht 05.11.2024 19:15:08
- Zuletzt bearbeitet 08.11.2024 21:09:45
Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manager has been fixed to only instantiate classes derive...
CVE-2024-51739
- EPSS 24.29%
- Veröffentlicht 05.11.2024 18:15:16
- Zuletzt bearbeitet 08.11.2024 15:56:18
Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if th...
CVE-2024-32870
- EPSS 16.84%
- Veröffentlicht 05.11.2024 00:15:04
- Zuletzt bearbeitet 13.11.2024 01:07:24
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2...
CVE-2024-31998
- EPSS 0.25%
- Veröffentlicht 05.11.2024 00:15:04
- Zuletzt bearbeitet 06.11.2024 14:31:46
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnera...
CVE-2023-34444
- EPSS 0.64%
- Veröffentlicht 05.11.2024 00:15:03
- Zuletzt bearbeitet 06.11.2024 14:28:46
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade...
CVE-2023-34443
- EPSS 0.13%
- Veröffentlicht 05.11.2024 00:15:03
- Zuletzt bearbeitet 06.11.2024 14:25:00
Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to...
CVE-2023-34445
- EPSS 0.64%
- Veröffentlicht 05.11.2024 00:15:03
- Zuletzt bearbeitet 06.11.2024 14:29:52
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. Th...