Combodo

Itop

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 13.01.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:07

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.

  • EPSS 0.23%
  • Veröffentlicht 13.01.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:06

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.

  • EPSS 0.2%
  • Veröffentlicht 13.01.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:07

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

  • EPSS 0.2%
  • Veröffentlicht 13.01.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:05:07

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

  • EPSS 0.29%
  • Veröffentlicht 12.01.2021 20:15:24
  • Zuletzt bearbeitet 21.11.2024 05:32:15

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user ...

  • EPSS 0.13%
  • Veröffentlicht 10.08.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:16

Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

  • EPSS 0.28%
  • Veröffentlicht 10.08.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:16

A security misconfiguration exists in Combodo iTop, which can expose sensitive information.

  • EPSS 0.28%
  • Veröffentlicht 10.08.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:16

Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

  • EPSS 0.31%
  • Veröffentlicht 10.08.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:16

Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.

  • EPSS 0.32%
  • Veröffentlicht 10.08.2020 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:16

A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.