
CVE-2021-41162 – Cross-site Scripting in Combodo iTop
https://notcve.org/view.php?id=CVE-2021-41162
21 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue. • https://github.com/Combodo/iTop/commit/83125d9ae16cfb2527b9d0ab0805a68b863244a0 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-41161 – XSS in csvimport in 3.0.0-beta versions
https://notcve.org/view.php?id=CVE-2021-41161
21 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue. Combodo iTop es una herramienta de administración de servicios de TI basada en la web. • https://github.com/Combodo/iTop/commit/c8f3d23d30c018bc44189b38fa34a5fffb4edb22 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-24811 – Cross-site Scripting in Combodo iTop
https://notcve.org/view.php?id=CVE-2022-24811
05 Apr 2022 — Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds. Combodi iTop es una herramienta de Administración de Servicios de TI basada en la web. • https://github.com/Combodo/iTop/commit/92a9a8c65f3cbb2cd4414ca3a3b45a5754ba57b4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-24780 – Code Injection in Combodo iTop
https://notcve.org/view.php?id=CVE-2022-24780
05 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds. Combodo iTop es una herramienta de Administración de Servicios de TI basada en la web. • https://packetstorm.news/files/id/167236 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2021-41245 – Possible Cross-Site Request Forgery in Combodo iTop
https://notcve.org/view.php?id=CVE-2021-41245
05 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file. Combodo iTop es una herramienta de administración de servicios de TI basada en la web. • https://github.com/Combodo/iTop/commit/7757f1f2d2330d49a3ebb40194f5ec4c8eaf8186 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-32664 – Reflected XSS in Combodo/iTop
https://notcve.org/view.php?id=CVE-2021-32664
19 Oct 2021 — Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5. Combodo iTop es una herramienta de Administración de Servicios de TI de código abierto basada en la web. En las versiones afectadas se presenta una vulnerabilidad de tipo XSS en la página "run query" cuando se inicia la sesión como administrador. • https://github.com/Combodo/iTop/commit/4f5c987d8b1bd12814dc606ea69b6cfb88490704 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-32663 – Unauthorized setup leads to SSRF in Combodo/iTop
https://notcve.org/view.php?id=CVE-2021-32663
19 Oct 2021 — iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later iTop es una herramienta de Administración de Servicios de TI de código abierto basada en la web. En las versiones afectadas un atacante puede llamar a la configuración del sistema sin autenticación. • https://github.com/Combodo/iTop/commit/43daa2ef088bf928a2386fa19324628c3f19b807 • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2021-32776 – No CSRF form token cleanup on Windows servers
https://notcve.org/view.php?id=CVE-2021-32776
21 Jul 2021 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0. Combodo iTop es una herramienta de Administración de servicios de TI basada en la web. En versiones anteriores a 2.7.4, los tokens CSRF pueden ser reusados por un usuario malicioso, ya que en los servidores Windows no se realiza una limpieza de los tokens CSRF. • https://github.com/Combodo/iTop/security/advisories/GHSA-cxw7-2x7h-f7pr • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-32775 – Any user can see any fields (including mailbox password) with GroupBy Dashlet
https://notcve.org/view.php?id=CVE-2021-32775
21 Jul 2021 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0. Combodo iTop es una herramienta de Administración de Servicios de TI basada en la web. En versiones anteriores a 2.7.4, un usuario no administrador puede acceder a muchos valores de clase/campo mediante el mensaje de error GroupBy Dashlet. • https://github.com/Combodo/iTop/security/advisories/GHSA-xh7w-rrp3-fhpq • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2021-21407 – Portal : the CSRF token isn't validated
https://notcve.org/view.php?id=CVE-2021-21407
21 Jul 2021 — Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0. Combodo iTop es una herramienta de Administración de servicios de TI de código abierto basada en la web. Anterior a versión 2.7.4, la comprobación del token CSRF puede ser omitida mediante el portal de iTop por medio de un procedimiento engañoso del navegador. • https://github.com/Combodo/iTop/security/advisories/GHSA-9wq8-4qm9-3j6f • CWE-352: Cross-Site Request Forgery (CSRF) •