PT-2022-11368 · Comodo+1 · Combodo Itop+1

Published

2022-04-21

·

Updated

2024-04-04

·

CVE-2021-41161

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 3.0.0-beta6
Description The issue affects Combodo iTop, a web-based IT Service Management tool. In the affected versions, the export CSV page does not properly escape user-supplied parameters, allowing for JavaScript injection into rendered CSV files. There are no known workarounds for this issue.
Recommendations For versions prior to 3.0.0-beta6, upgrade to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the export CSV page until an upgrade can be performed. Avoid using user-supplied parameters in the export CSV functionality until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2021-41161
GHSA-788F-G6G9-F8FC

Affected Products

Alt Linux
Combodo Itop