Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 12 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 22:30:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Cross-Site Request Forgery (CSRF) in several iTop pages
Weaknesses CWE-352
References
Metrics cvssV3_0

{'score': 7.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-08T22:16:35.543Z

Updated: 2024-11-12T15:23:26.819Z

Reserved: 2024-11-04T17:46:16.778Z

Link: CVE-2024-52002

cve-icon Vulnrichment

Updated: 2024-11-12T15:23:23.263Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T23:15:04.410

Modified: 2024-11-12T13:56:54.483

Link: CVE-2024-52002

cve-icon Redhat

No data.