Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-4079

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.0%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 4.0
Products affected by CVE-2020-4079
  • Combodo » Itop » Version: N/A
    cpe:2.3:a:combodo:itop:-
  • Combodo » Itop » Version: 0.7.1
    cpe:2.3:a:combodo:itop:0.7.1
  • Combodo » Itop » Version: 0.7.2
    cpe:2.3:a:combodo:itop:0.7.2
  • Combodo » Itop » Version: 0.8
    cpe:2.3:a:combodo:itop:0.8
  • Combodo » Itop » Version: 0.8.0
    cpe:2.3:a:combodo:itop:0.8.0
  • Combodo » Itop » Version: 0.8.1.3
    cpe:2.3:a:combodo:itop:0.8.1.3
  • Combodo » Itop » Version: 0.9
    cpe:2.3:a:combodo:itop:0.9
  • Combodo » Itop » Version: 0.9.1
    cpe:2.3:a:combodo:itop:0.9.1
  • Combodo » Itop » Version: 1.0
    cpe:2.3:a:combodo:itop:1.0
  • Combodo » Itop » Version: 1.0.0
    cpe:2.3:a:combodo:itop:1.0.0
  • Combodo » Itop » Version: 1.0.1
    cpe:2.3:a:combodo:itop:1.0.1
  • Combodo » Itop » Version: 1.0.2
    cpe:2.3:a:combodo:itop:1.0.2
  • Combodo » Itop » Version: 1.1
    cpe:2.3:a:combodo:itop:1.1
  • Combodo » Itop » Version: 1.1.0
    cpe:2.3:a:combodo:itop:1.1.0
  • Combodo » Itop » Version: 1.1.181
    cpe:2.3:a:combodo:itop:1.1.181
  • Combodo » Itop » Version: 1.2
    cpe:2.3:a:combodo:itop:1.2
  • Combodo » Itop » Version: 1.2.0
    cpe:2.3:a:combodo:itop:1.2.0
  • Combodo » Itop » Version: 1.2.1
    cpe:2.3:a:combodo:itop:1.2.1
  • Combodo » Itop » Version: 2.0
    cpe:2.3:a:combodo:itop:2.0
  • Combodo » Itop » Version: 2.0.0
    cpe:2.3:a:combodo:itop:2.0.0
  • Combodo » Itop » Version: 2.0.1
    cpe:2.3:a:combodo:itop:2.0.1
  • Combodo » Itop » Version: 2.0.2
    cpe:2.3:a:combodo:itop:2.0.2
  • Combodo » Itop » Version: 2.0.3
    cpe:2.3:a:combodo:itop:2.0.3
  • Combodo » Itop » Version: 2.1.0
    cpe:2.3:a:combodo:itop:2.1.0
  • Combodo » Itop » Version: 2.2.0
    cpe:2.3:a:combodo:itop:2.2.0
  • Combodo » Itop » Version: 2.2.1
    cpe:2.3:a:combodo:itop:2.2.1
  • Combodo » Itop » Version: 2.3.0
    cpe:2.3:a:combodo:itop:2.3.0
  • Combodo » Itop » Version: 2.3.1
    cpe:2.3:a:combodo:itop:2.3.1
  • Combodo » Itop » Version: 2.3.2
    cpe:2.3:a:combodo:itop:2.3.2
  • Combodo » Itop » Version: 2.3.3
    cpe:2.3:a:combodo:itop:2.3.3
  • Combodo » Itop » Version: 2.3.4
    cpe:2.3:a:combodo:itop:2.3.4
  • Combodo » Itop » Version: 2.4.0
    cpe:2.3:a:combodo:itop:2.4.0
  • Combodo » Itop » Version: 2.4.1
    cpe:2.3:a:combodo:itop:2.4.1
  • Combodo » Itop » Version: 2.4.2
    cpe:2.3:a:combodo:itop:2.4.2
  • Combodo » Itop » Version: 2.4.3
    cpe:2.3:a:combodo:itop:2.4.3
  • Combodo » Itop » Version: 2.5.0
    cpe:2.3:a:combodo:itop:2.5.0
  • Combodo » Itop » Version: 2.5.1
    cpe:2.3:a:combodo:itop:2.5.1
  • Combodo » Itop » Version: 2.6.0
    cpe:2.3:a:combodo:itop:2.6.0
  • Combodo » Itop » Version: 2.6.1
    cpe:2.3:a:combodo:itop:2.6.1
  • Combodo » Itop » Version: 2.6.3
    cpe:2.3:a:combodo:itop:2.6.3
  • Combodo » Itop » Version: 2.6.4
    cpe:2.3:a:combodo:itop:2.6.4
  • Combodo » Itop » Version: 2.7
    cpe:2.3:a:combodo:itop:2.7
  • Combodo » Itop » Version: 2.7.0
    cpe:2.3:a:combodo:itop:2.7.0
  • Combodo » Itop » Version: 2.7.0-1
    cpe:2.3:a:combodo:itop:2.7.0-1
  • Combodo » Itop » Version: 2.7.0-2
    cpe:2.3:a:combodo:itop:2.7.0-2
  • Combodo » Itop » Version: 2.7.1
    cpe:2.3:a:combodo:itop:2.7.1
  • Combodo » Itop » Version: 2.7.3
    cpe:2.3:a:combodo:itop:2.7.3


Contact Us

Shodan ® - All rights reserved