Show filters
66 Total Results
Displaying 21-30 of 66
Sort by:
Attacker Value
Unknown
CVE-2023-47622
Disclosure Date: April 15, 2024 (last updated February 07, 2025)
iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.
0
Attacker Value
Unknown
CVE-2023-47123
Disclosure Date: April 15, 2024 (last updated February 07, 2025)
iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.
0
Attacker Value
Unknown
CVE-2023-45808
Disclosure Date: April 15, 2024 (last updated February 07, 2025)
iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an out of scope Organization). Fixed in iTop 2.7.10, 3.0.4, 3.1.1, and 3.2.0.
0
Attacker Value
Unknown
CVE-2023-44396
Disclosure Date: April 15, 2024 (last updated February 07, 2025)
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.
0
Attacker Value
Unknown
CVE-2023-43790
Disclosure Date: April 15, 2024 (last updated February 07, 2025)
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.
0
Attacker Value
Unknown
CVE-2023-47489
Disclosure Date: November 09, 2023 (last updated January 11, 2024)
CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.
0
Attacker Value
Unknown
CVE-2023-47488
Disclosure Date: November 09, 2023 (last updated November 17, 2023)
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.
0
Attacker Value
Unknown
CVE-2023-34447
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
0
Attacker Value
Unknown
CVE-2023-34446
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
0
Attacker Value
Unknown
CVE-2022-39216
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.
0