CVE-2021-41161
- EPSS 0.65%
- Veröffentlicht 21.04.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:38
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. ...
CVE-2021-41162
- EPSS 0.65%
- Veröffentlicht 21.04.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:38
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. ...
CVE-2022-24780
- EPSS 5.34%
- Veröffentlicht 05.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:04
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server ...
CVE-2022-24811
- EPSS 0.74%
- Veröffentlicht 05.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:09
Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There ar...
CVE-2021-41245
- EPSS 0.69%
- Veröffentlicht 05.04.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:52
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the ...
CVE-2021-32663
- EPSS 1.46%
- Veröffentlicht 19.10.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:29
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 ...
CVE-2021-32664
- EPSS 0.83%
- Veröffentlicht 19.10.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:29
Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.
CVE-2021-32775
- EPSS 0.78%
- Veröffentlicht 21.07.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:42
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.
CVE-2021-32776
- EPSS 0.38%
- Veröffentlicht 21.07.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:43
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.
CVE-2021-21407
- EPSS 0.46%
- Veröffentlicht 21.07.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:48:17
Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.