Combodo

Itop

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 09.11.2023 06:15:24
  • Zuletzt bearbeitet 29.09.2025 14:16:41

CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.

  • EPSS 4.63%
  • Veröffentlicht 09.11.2023 06:15:24
  • Zuletzt bearbeitet 29.09.2025 14:16:41

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact pag...

  • EPSS 1.18%
  • Veröffentlicht 25.10.2023 18:17:28
  • Zuletzt bearbeitet 21.11.2024 08:07:16

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

  • EPSS 0.78%
  • Veröffentlicht 25.10.2023 18:17:28
  • Zuletzt bearbeitet 21.11.2024 08:07:16

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

  • EPSS 0.31%
  • Veröffentlicht 14.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:48

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2...

  • EPSS 2.51%
  • Veröffentlicht 14.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:48

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7....

Exploit
  • EPSS 3.15%
  • Veröffentlicht 14.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:27

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

Exploit
  • EPSS 16.68%
  • Veröffentlicht 10.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:27

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 21.04.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:17

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to author...

  • EPSS 0.31%
  • Veröffentlicht 21.04.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:38

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. ...