PT-2022-11369 · Comodo+1 · Itop+1

Accognet

·

Published

2022-04-21

·

Updated

2024-04-04

·

CVE-2021-41162

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions 3.0.0 beta releases prior to beta6
Description The issue concerns a web-based IT Service Management tool where the ajax.render.php?operation=wizard helper page did not properly escape user-supplied parameters, allowing for a cross-site scripting attack vector. Users are advised to upgrade as there are no known workarounds for this issue.
Recommendations For versions 3.0.0 beta releases prior to beta6, upgrade to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the ajax.render.php?operation=wizard helper page until an upgrade is possible.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2021-41162
GHSA-W5JW-HFVP-GX95

Affected Products

Alt Linux
Itop