CVE-2023-48709
iTop vulnerable to potential formula injection in Excel/CSV export file
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.
iTop es una plataforma de gestión de servicios de TI. Al exportar datos desde el backoffice o el portal en archivos CSV o Excel, las entradas de los usuarios pueden incluir fórmulas maliciosas que pueden importarse a Excel. Como Excel 2016 **no** impide la ejecución remota de código de forma predeterminada, los usuarios desinformados pueden convertirse en víctimas. Esta vulnerabilidad se solucionó en 2.7.9, 3.0.4, 3.1.1 y 3.2.0.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-17 CVE Reserved
- 2024-04-15 CVE Published
- 2024-04-16 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/Combodo/iTop/commit/083a0b79bfa2c106735b5c10eddb35a05ec7f04a | X_refsource_misc | |
https://github.com/Combodo/iTop/commit/b10bcb976dfe8e55aa0f659bfbcdd18334a1b17c | X_refsource_misc | |
https://github.com/Combodo/iTop/security/advisories/GHSA-9q3x-9987-53x9 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Combodo Search vendor "Combodo" | ITop Search vendor "Combodo" for product "ITop" | < 2.7.9 Search vendor "Combodo" for product "ITop" and version " < 2.7.9" | en |
Affected
| ||||||
Combodo Search vendor "Combodo" | ITop Search vendor "Combodo" for product "ITop" | >= 3.0.0 < 3.0.4 Search vendor "Combodo" for product "ITop" and version " >= 3.0.0 < 3.0.4" | en |
Affected
| ||||||
Combodo Search vendor "Combodo" | ITop Search vendor "Combodo" for product "ITop" | >= 3.1.0 < 3.1.1 Search vendor "Combodo" for product "ITop" and version " >= 3.1.0 < 3.1.1" | en |
Affected
|