PT-2022-11379 · Comodo+1 · Combodo Itop+1

Amammad

·

Published

2022-04-05

·

Updated

2024-04-04

·

CVE-2021-41245

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.6 and 3.0.0
Description Combodo iTop is a web-based IT Service Management tool. In the affected versions, CSRF tokens generated by privUITransactionFile are not properly checked.
Recommendations For versions prior to 2.7.6, update to version 2.7.6 to resolve the issue. For versions prior to 3.0.0, update to version 3.0.0 to resolve the issue. As a temporary workaround for affected versions, use the session implementation by adding it to the iTop config file.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1879
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
CVE-2021-41245
GHSA-33PR-5776-9JQF

Affected Products

Alt Linux
Combodo Itop