PT-2022-4549 · Comodo+1 · Itop+1
Markus Krell
·
Published
2020-04-09
·
Updated
2025-03-14
·
CVE-2022-24780
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Combodo iTop versions prior to 2.7.6 and 3.0.0
Description
The issue is related to incorrect code generation management in the iTop web-based IT Service Management tool. It allows users of the iTop user portal to send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges.
Recommendations
For versions prior to 2.7.6, update to version 2.7.6 or later.
For versions prior to 3.0.0, update to version 3.0.0 or later.
As a temporary workaround, consider restricting access to the iTop user portal until a patch is applied.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Itop