PT-2024-35083 · Comodo · Itop

Bengrenoble

·

Published

2024-11-07

·

Updated

2024-11-08

·

CVE-2024-51994

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 3.2.0
Description The issue is related to a Cross-site Scripting (XSS) vulnerability that can be triggered by uploading a text file containing JavaScript to the portal. This is a web-based IT Service Management tool.
Recommendations For versions prior to 3.2.0, upgrade to version 3.2.0 to address the issue. As a temporary workaround, consider restricting the upload of text files to the portal until the upgrade is applied. Avoid using the portal's file upload feature with untrusted input until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51994
GHSA-JJPH-C25G-5C7G

Affected Products

Itop