CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 29 Sep 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-29T13:40:42.397Z
Reserved: 2023-11-06T00:00:00.000Z
Link: CVE-2023-47489
No data.
Status : Modified
Published: 2023-11-09T06:15:24.347
Modified: 2025-09-29T14:16:41.850
Link: CVE-2023-47489
No data.
OpenCVE Enrichment
No data.
Weaknesses