CVE-2024-54139

Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the `_table_id` parameter. Versions 2.7.11, 3.1.2, and 3.2.0 contain a patch for the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:rc3:*:*:*:*:*:*

History

11 Mar 2025, 16:44

Type Values Removed Values Added
First Time Combodo
Combodo itop
References () https://github.com/Combodo/iTop/security/advisories/GHSA-jmv2-wfh5-h5wg - () https://github.com/Combodo/iTop/security/advisories/GHSA-jmv2-wfh5-h5wg - Vendor Advisory
CPE cpe:2.3:a:combodo:itop:3.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.2.0:alpha1:*:*:*:*:*:*

13 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-13 16:15

Updated : 2025-03-11 16:44


NVD link : CVE-2024-54139

Mitre link : CVE-2024-54139

CVE.ORG link : CVE-2024-54139


JSON object : View

Products Affected

combodo

  • itop
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-352

Cross-Site Request Forgery (CSRF)