// For flags

CVE-2023-48709

iTop vulnerable to potential formula injection in Excel/CSV export file

Severity Score

8.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.

iTop es una plataforma de gestión de servicios de TI. Al exportar datos desde el backoffice o el portal en archivos CSV o Excel, las entradas de los usuarios pueden incluir fórmulas maliciosas que pueden importarse a Excel. Como Excel 2016 **no** impide la ejecución remota de código de forma predeterminada, los usuarios desinformados pueden convertirse en víctimas. Esta vulnerabilidad se solucionó en 2.7.9, 3.0.4, 3.1.1 y 3.2.0.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2023-11-17 CVE Reserved
  • 2024-04-15 CVE Published
  • 2024-04-16 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Combodo
Search vendor "Combodo"
ITop
Search vendor "Combodo" for product "ITop"
< 2.7.9
Search vendor "Combodo" for product "ITop" and version " < 2.7.9"
en
Affected
Combodo
Search vendor "Combodo"
ITop
Search vendor "Combodo" for product "ITop"
>= 3.0.0 < 3.0.4
Search vendor "Combodo" for product "ITop" and version " >= 3.0.0 < 3.0.4"
en
Affected
Combodo
Search vendor "Combodo"
ITop
Search vendor "Combodo" for product "ITop"
>= 3.1.0 < 3.1.1
Search vendor "Combodo" for product "ITop" and version " >= 3.1.0 < 3.1.1"
en
Affected