Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-13965

Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2019-13965
  • Combodo » Itop » Version: N/A
    cpe:2.3:a:combodo:itop:-
  • Combodo » Itop » Version: 0.7.1
    cpe:2.3:a:combodo:itop:0.7.1
  • Combodo » Itop » Version: 0.7.2
    cpe:2.3:a:combodo:itop:0.7.2
  • Combodo » Itop » Version: 0.8
    cpe:2.3:a:combodo:itop:0.8
  • Combodo » Itop » Version: 0.8.0
    cpe:2.3:a:combodo:itop:0.8.0
  • Combodo » Itop » Version: 0.8.1.3
    cpe:2.3:a:combodo:itop:0.8.1.3
  • Combodo » Itop » Version: 0.9
    cpe:2.3:a:combodo:itop:0.9
  • Combodo » Itop » Version: 0.9.1
    cpe:2.3:a:combodo:itop:0.9.1
  • Combodo » Itop » Version: 1.0
    cpe:2.3:a:combodo:itop:1.0
  • Combodo » Itop » Version: 1.0.0
    cpe:2.3:a:combodo:itop:1.0.0
  • Combodo » Itop » Version: 1.0.1
    cpe:2.3:a:combodo:itop:1.0.1
  • Combodo » Itop » Version: 1.0.2
    cpe:2.3:a:combodo:itop:1.0.2
  • Combodo » Itop » Version: 1.1
    cpe:2.3:a:combodo:itop:1.1
  • Combodo » Itop » Version: 1.1.0
    cpe:2.3:a:combodo:itop:1.1.0
  • Combodo » Itop » Version: 1.1.181
    cpe:2.3:a:combodo:itop:1.1.181
  • Combodo » Itop » Version: 1.2
    cpe:2.3:a:combodo:itop:1.2
  • Combodo » Itop » Version: 1.2.0
    cpe:2.3:a:combodo:itop:1.2.0
  • Combodo » Itop » Version: 1.2.1
    cpe:2.3:a:combodo:itop:1.2.1
  • Combodo » Itop » Version: 2.0
    cpe:2.3:a:combodo:itop:2.0
  • Combodo » Itop » Version: 2.0.0
    cpe:2.3:a:combodo:itop:2.0.0
  • Combodo » Itop » Version: 2.0.1
    cpe:2.3:a:combodo:itop:2.0.1
  • Combodo » Itop » Version: 2.0.2
    cpe:2.3:a:combodo:itop:2.0.2
  • Combodo » Itop » Version: 2.0.3
    cpe:2.3:a:combodo:itop:2.0.3
  • Combodo » Itop » Version: 2.1.0
    cpe:2.3:a:combodo:itop:2.1.0
  • Combodo » Itop » Version: 2.2.0
    cpe:2.3:a:combodo:itop:2.2.0
  • Combodo » Itop » Version: 2.2.1
    cpe:2.3:a:combodo:itop:2.2.1
  • Combodo » Itop » Version: 2.3.0
    cpe:2.3:a:combodo:itop:2.3.0
  • Combodo » Itop » Version: 2.3.1
    cpe:2.3:a:combodo:itop:2.3.1
  • Combodo » Itop » Version: 2.3.2
    cpe:2.3:a:combodo:itop:2.3.2
  • Combodo » Itop » Version: 2.3.3
    cpe:2.3:a:combodo:itop:2.3.3
  • Combodo » Itop » Version: 2.3.4
    cpe:2.3:a:combodo:itop:2.3.4
  • Combodo » Itop » Version: 2.4.0
    cpe:2.3:a:combodo:itop:2.4.0
  • Combodo » Itop » Version: 2.4.1
    cpe:2.3:a:combodo:itop:2.4.1
  • Combodo » Itop » Version: 2.4.2
    cpe:2.3:a:combodo:itop:2.4.2
  • Combodo » Itop » Version: 2.4.3
    cpe:2.3:a:combodo:itop:2.4.3
  • Combodo » Itop » Version: 2.5.0
    cpe:2.3:a:combodo:itop:2.5.0
  • Combodo » Itop » Version: 2.5.1
    cpe:2.3:a:combodo:itop:2.5.1
  • Combodo » Itop » Version: 2.6.0
    cpe:2.3:a:combodo:itop:2.6.0


Contact Us

Shodan ® - All rights reserved