Page 5 of 71 results (0.003 seconds)

CVSS: 9.3EPSS: 0%CPEs: 6EXPL: 0

21 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue. Combodo iTop es una herramienta de administración de servicios de TI basada en la web. • https://github.com/Combodo/iTop/commit/c8f3d23d30c018bc44189b38fa34a5fffb4edb22 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

05 Apr 2022 — Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds. Combodi iTop es una herramienta de Administración de Servicios de TI basada en la web. • https://github.com/Combodo/iTop/commit/92a9a8c65f3cbb2cd4414ca3a3b45a5754ba57b4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 16%CPEs: 12EXPL: 4

05 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds. Combodo iTop es una herramienta de Administración de Servicios de TI basada en la web. • https://packetstorm.news/files/id/167236 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 1

05 Apr 2022 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file. Combodo iTop es una herramienta de administración de servicios de TI basada en la web. • https://github.com/Combodo/iTop/commit/7757f1f2d2330d49a3ebb40194f5ec4c8eaf8186 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.1EPSS: 0%CPEs: 2EXPL: 0

19 Oct 2021 — Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5. Combodo iTop es una herramienta de Administración de Servicios de TI de código abierto basada en la web. En las versiones afectadas se presenta una vulnerabilidad de tipo XSS en la página "run query" cuando se inicia la sesión como administrador. • https://github.com/Combodo/iTop/commit/4f5c987d8b1bd12814dc606ea69b6cfb88490704 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.7EPSS: 0%CPEs: 2EXPL: 0

19 Oct 2021 — iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later iTop es una herramienta de Administración de Servicios de TI de código abierto basada en la web. En las versiones afectadas un atacante puede llamar a la configuración del sistema sin autenticación. • https://github.com/Combodo/iTop/commit/43daa2ef088bf928a2386fa19324628c3f19b807 • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

21 Jul 2021 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0. Combodo iTop es una herramienta de Administración de servicios de TI basada en la web. En versiones anteriores a 2.7.4, los tokens CSRF pueden ser reusados por un usuario malicioso, ya que en los servidores Windows no se realiza una limpieza de los tokens CSRF. • https://github.com/Combodo/iTop/security/advisories/GHSA-cxw7-2x7h-f7pr • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.7EPSS: 0%CPEs: 4EXPL: 0

21 Jul 2021 — Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0. Combodo iTop es una herramienta de Administración de Servicios de TI basada en la web. En versiones anteriores a 2.7.4, un usuario no administrador puede acceder a muchos valores de clase/campo mediante el mensaje de error GroupBy Dashlet. • https://github.com/Combodo/iTop/security/advisories/GHSA-xh7w-rrp3-fhpq • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 8.0EPSS: 0%CPEs: 1EXPL: 0

21 Jul 2021 — Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0. Combodo iTop es una herramienta de Administración de servicios de TI de código abierto basada en la web. Anterior a versión 2.7.4, la comprobación del token CSRF puede ser omitida mediante el portal de iTop por medio de un procedimiento engañoso del navegador. • https://github.com/Combodo/iTop/security/advisories/GHSA-9wq8-4qm9-3j6f • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 0

21 Jul 2021 — Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0. Combodo iTop es una herramienta de administración de servicios de TI de código abierto basada en la web. En versiones anteriores a 2.7.4, se presenta una vulnerabilidad de inyección de comandos en el Asistente de Configuración cuando se proporciona la r... • https://github.com/Combodo/iTop/security/advisories/GHSA-pf95-6h7q-q85x • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •