Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Combodo
Combodo itop |
|
CPEs | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* | |
Vendors & Products |
Combodo
Combodo itop |
|
Metrics |
ssvc
|
Mon, 04 Nov 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | CSRF security issue on CSV import in Combodo iTop | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-04T23:35:22.676Z
Updated: 2024-11-05T16:27:54.054Z
Reserved: 2024-04-08T13:48:37.492Z
Link: CVE-2024-31998
Vulnrichment
Updated: 2024-11-05T16:27:49.619Z
NVD
Status : Analyzed
Published: 2024-11-05T00:15:04.083
Modified: 2024-11-06T14:31:46.643
Link: CVE-2024-31998
Redhat
No data.