PT-2018-10022 · Comodo+1 · Itop+1
Ayoub Arbah
·
Published
2018-05-02
·
Updated
2019-10-03
·
CVE-2018-10642
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Combodo iTop version 2.4.1
Description
The issue allows remote authenticated administrators to execute arbitrary commands by modifying the platform configuration. This is due to the presence of a function called TestConfig() in web/env-production/itop-config/config.php, which calls the vulnerable function
eval().Recommendations
For Combodo iTop version 2.4.1, consider disabling the
TestConfig() function or restricting access to the configuration modification feature until a patch is available. As a temporary workaround, avoid using the eval() function in the config.php file to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Itop