CVE-2020-4079
Information disclosure vulnerability in iTop
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.
Combodo iTop es una herramienta de IT Service Management basada en la web. En iTop versiones anteriores a 2.7.2 y 2.8.0, cuando el endpoint ajax para la funcionalidad del portal "excel export" es llamado directamente, permite obtener datos sin filtrado de alcance. Esto permite a un usuario acceder a datos a los que no deberÃa tener acceso. Esto es corregido en las versiones 2.7.2 y 3.0.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-30 CVE Reserved
- 2021-01-12 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/Combodo/iTop/security/advisories/GHSA-vcv9-xp3j-7jwh | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Combodo Search vendor "Combodo" | Itop Search vendor "Combodo" for product "Itop" | < 2.7.2 Search vendor "Combodo" for product "Itop" and version " < 2.7.2" | - |
Affected
| ||||||
Combodo Search vendor "Combodo" | Itop Search vendor "Combodo" for product "Itop" | 2.7.3 Search vendor "Combodo" for product "Itop" and version "2.7.3" | - |
Affected
|