PT-2022-4549 · Comodo+1 · Itop+1

Markus Krell

·

Published

2020-04-09

·

Updated

2025-03-14

·

CVE-2022-24780

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.6 and 3.0.0
Description The issue is related to incorrect code generation management in the iTop web-based IT Service Management tool. It allows users of the iTop user portal to send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges.
Recommendations For versions prior to 2.7.6, update to version 2.7.6 or later. For versions prior to 3.0.0, update to version 3.0.0 or later. As a temporary workaround, consider restricting access to the iTop user portal until a patch is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1700
ALT-PU-2023-1879
ALT-PU-2023-6184
ALT-PU-2024-1028
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
ALT-PU-2025-4212
BDU:2022-05425
CVE-2022-24780
GHSA-V97M-WGXQ-RH54

Affected Products

Alt Linux
Itop