Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 05 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Combodo
Combodo itop
CPEs cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
Vendors & Products Combodo
Combodo itop
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 Nov 2024 23:45:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Cross-site Scripting vulnerability in the run_query.php page in Combodo iTop
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-04T23:29:00.751Z

Updated: 2024-11-05T16:34:56.924Z

Reserved: 2023-06-06T16:16:53.557Z

Link: CVE-2023-34443

cve-icon Vulnrichment

Updated: 2024-11-05T16:34:51.699Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-05T00:15:03.103

Modified: 2024-11-06T14:25:00.830

Link: CVE-2023-34443

cve-icon Redhat

No data.