PT-2024-35084 · Comodo · Combodo Itop

Defencetechsecurity

·

Published

2024-11-07

·

Updated

2025-03-27

·

CVE-2024-51995

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 3.2.0
Description Combodo iTop is a web-based IT Service Management tool. An issue allows an attacker to request any route as long as they specify an operation that is allowed. The estimated number of potentially affected devices worldwide is not available. There are no known real-world incidents where this issue was exploited.
Recommendations For versions prior to 3.2.0, upgrade to version 3.2.0 to address the issue. As a temporary workaround, consider restricting access to the ajax.render.php page to minimize the risk of exploitation. Avoid using arbitrary routes in the affected API endpoints until the issue is resolved.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-51995
GHSA-3MXR-8R3J-J2J9

Affected Products

Combodo Itop