PT-2021-14484 · Comodo+1 · Combodo Itop+1

Mushrraf Baig Ashraf

·

Published

2021-07-21

·

Updated

2024-04-04

·

CVE-2021-21407

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.4 Combodo iTop versions prior to 3.0.0 can be simplified to the above, as versions prior to 2.7.4 already include versions prior to 3.0.0. Therefore, the simplified version is: Combodo iTop versions prior to 2.7.4
Description The issue concerns the CSRF token validation in Combodo iTop, which can be bypassed through the iTop portal using a specific browser procedure.
Recommendations For versions prior to 2.7.4, update to version 2.7.4 or later to resolve the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2021-21407
GHSA-9WQ8-4QM9-3J6F

Affected Products

Alt Linux
Combodo Itop