Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Amammad

Researcher fromHuntr
#31377of 53,611
8.1Total CVSS
Vulnerabilities · 1
PT-2022-11379
8.1
2022-04-05
Comodo · Combodo Itop · CVE-2021-41245
**Name of the Vulnerable Software and Affected Versions** Combodo iTop versions prior to 2.7.6 and 3.0.0 **Description** Combodo iTop is a web-based IT Service Management tool. In the affected versions, CSRF tokens generated by `privUITransactionFile` are not properly checked. **Recommendations** For versions prior to 2.7.6, update to version 2.7.6 to resolve the issue. For versions prior to 3.0.0, update to version 3.0.0 to resolve the issue. As a temporary workaround for affected versions, use the session implementation by adding it to the iTop config file.