CVE-2023-47489
- EPSS 0.12%
- Veröffentlicht 09.11.2023 06:15:24
- Zuletzt bearbeitet 29.09.2025 14:16:41
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.
CVE-2023-47488
- EPSS 4.63%
- Veröffentlicht 09.11.2023 06:15:24
- Zuletzt bearbeitet 29.09.2025 14:16:41
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact pag...
CVE-2023-34447
- EPSS 1.18%
- Veröffentlicht 25.10.2023 18:17:28
- Zuletzt bearbeitet 21.11.2024 08:07:16
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
CVE-2023-34446
- EPSS 0.78%
- Veröffentlicht 25.10.2023 18:17:28
- Zuletzt bearbeitet 21.11.2024 08:07:16
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
CVE-2022-39216
- EPSS 0.31%
- Veröffentlicht 14.03.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:48
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2...
CVE-2022-39214
- EPSS 2.51%
- Veröffentlicht 14.03.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:48
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7....
CVE-2022-31403
- EPSS 3.15%
- Veröffentlicht 14.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:27
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.
CVE-2022-31402
- EPSS 16.68%
- Veröffentlicht 10.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:27
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
CVE-2022-24870
- EPSS 0.43%
- Veröffentlicht 21.04.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:17
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to author...
CVE-2021-41162
- EPSS 0.31%
- Veröffentlicht 21.04.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:38
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. ...