Combodo

Itop

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 21.04.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:38

Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 05.04.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:09

Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There ar...

Exploit
  • EPSS 20.74%
  • Veröffentlicht 05.04.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:04

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server ...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 05.04.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:52

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the ...

  • EPSS 0.42%
  • Veröffentlicht 19.10.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:29

Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.

  • EPSS 0.32%
  • Veröffentlicht 19.10.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:29

iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 ...

  • EPSS 0.14%
  • Veröffentlicht 21.07.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:43

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.

  • EPSS 0.29%
  • Veröffentlicht 21.07.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:42

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.

  • EPSS 0.15%
  • Veröffentlicht 21.07.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:48:17

Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.

  • EPSS 0.73%
  • Veröffentlicht 21.07.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:48:17

Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 an...