Skip to main content

Vendor/product archive

combodo / itop CVEs

Beta · best-effort

81 CVEs tagged to combodo / itop4 Critical, 39 High, 37 Medium, 1 Low, 0 Unrated.

CVE-2024-32870

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31998

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31448

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can be performed when importing th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34445

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34444

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34443

Published Nov 5, 2024

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This h…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48710

Published Apr 15, 2024

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensiti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-48709

Published Apr 15, 2024

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47626

Published Apr 15, 2024

iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47622

Published Apr 15, 2024

iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47123

Published Apr 15, 2024

iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displaye…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45808

Published Apr 15, 2024

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http re…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44396

Published Apr 15, 2024

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43790

Published Apr 15, 2024

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerabil…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38511

Published Apr 15, 2024

iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47489

Published Nov 9, 2023

CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php comp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47488

Published Nov 9, 2023

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34447

Published Oct 25, 2023

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in ve…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34446

Published Oct 25, 2023

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. Thi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39216

Published Mar 14, 2023

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness paramet…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39214

Published Mar 14, 2023

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-31403

Published Jun 14, 2022

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31402

Published Jun 10, 2022

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24870

Published Apr 21, 2022

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechani…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41162

Published Apr 21, 2022

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-50 of 81 CVEsPage 2 of 4