Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can be performed when importing this content. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. Users unable to upgrade should validate CSV content before importing it.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/Combodo/iTop/security/advisories/GHSA-776w-x6v7-vfwf | Vendor Advisory | 
Configurations
                    History
                    06 Nov 2024, 14:31
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.1 | 
| First Time | Combodo itop Combodo | |
| References | () https://github.com/Combodo/iTop/security/advisories/GHSA-776w-x6v7-vfwf - Vendor Advisory | |
| CPE | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* | 
05 Nov 2024, 16:04
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
05 Nov 2024, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-11-05 00:15
Updated : 2024-11-06 14:31
NVD link : CVE-2024-31448
Mitre link : CVE-2024-31448
CVE.ORG link : CVE-2024-31448
JSON object : View
Products Affected
                combodo
- itop
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
