Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
References
Link | Resource |
---|---|
https://github.com/Combodo/iTop/security/advisories/GHSA-rwx9-rcxf-qrwv | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
06 Nov 2024, 14:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Combodo/iTop/security/advisories/GHSA-rwx9-rcxf-qrwv - Vendor Advisory | |
First Time |
Combodo itop
Combodo |
|
CPE | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
05 Nov 2024, 16:04
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
05 Nov 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-05 00:15
Updated : 2024-11-06 14:28
NVD link : CVE-2023-34444
Mitre link : CVE-2023-34444
CVE.ORG link : CVE-2023-34444
JSON object : View
Products Affected
combodo
- itop
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')