Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-24780

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.165
EPSS Ranking 94.6%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
References
Products affected by CVE-2022-24780
  • Combodo » Itop » Version: N/A
    cpe:2.3:a:combodo:itop:-
  • Combodo » Itop » Version: 0.7.1
    cpe:2.3:a:combodo:itop:0.7.1
  • Combodo » Itop » Version: 0.7.2
    cpe:2.3:a:combodo:itop:0.7.2
  • Combodo » Itop » Version: 0.8
    cpe:2.3:a:combodo:itop:0.8
  • Combodo » Itop » Version: 0.8.0
    cpe:2.3:a:combodo:itop:0.8.0
  • Combodo » Itop » Version: 0.8.1.3
    cpe:2.3:a:combodo:itop:0.8.1.3
  • Combodo » Itop » Version: 0.9
    cpe:2.3:a:combodo:itop:0.9
  • Combodo » Itop » Version: 0.9.1
    cpe:2.3:a:combodo:itop:0.9.1
  • Combodo » Itop » Version: 1.0
    cpe:2.3:a:combodo:itop:1.0
  • Combodo » Itop » Version: 1.0.0
    cpe:2.3:a:combodo:itop:1.0.0
  • Combodo » Itop » Version: 1.0.1
    cpe:2.3:a:combodo:itop:1.0.1
  • Combodo » Itop » Version: 1.0.2
    cpe:2.3:a:combodo:itop:1.0.2
  • Combodo » Itop » Version: 1.1
    cpe:2.3:a:combodo:itop:1.1
  • Combodo » Itop » Version: 1.1.0
    cpe:2.3:a:combodo:itop:1.1.0
  • Combodo » Itop » Version: 1.1.181
    cpe:2.3:a:combodo:itop:1.1.181
  • Combodo » Itop » Version: 1.2
    cpe:2.3:a:combodo:itop:1.2
  • Combodo » Itop » Version: 1.2.0
    cpe:2.3:a:combodo:itop:1.2.0
  • Combodo » Itop » Version: 1.2.1
    cpe:2.3:a:combodo:itop:1.2.1
  • Combodo » Itop » Version: 2.0
    cpe:2.3:a:combodo:itop:2.0
  • Combodo » Itop » Version: 2.0.0
    cpe:2.3:a:combodo:itop:2.0.0
  • Combodo » Itop » Version: 2.0.1
    cpe:2.3:a:combodo:itop:2.0.1
  • Combodo » Itop » Version: 2.0.2
    cpe:2.3:a:combodo:itop:2.0.2
  • Combodo » Itop » Version: 2.0.3
    cpe:2.3:a:combodo:itop:2.0.3
  • Combodo » Itop » Version: 2.1.0
    cpe:2.3:a:combodo:itop:2.1.0
  • Combodo » Itop » Version: 2.2.0
    cpe:2.3:a:combodo:itop:2.2.0
  • Combodo » Itop » Version: 2.2.1
    cpe:2.3:a:combodo:itop:2.2.1
  • Combodo » Itop » Version: 2.3.0
    cpe:2.3:a:combodo:itop:2.3.0
  • Combodo » Itop » Version: 2.3.1
    cpe:2.3:a:combodo:itop:2.3.1
  • Combodo » Itop » Version: 2.3.2
    cpe:2.3:a:combodo:itop:2.3.2
  • Combodo » Itop » Version: 2.3.3
    cpe:2.3:a:combodo:itop:2.3.3
  • Combodo » Itop » Version: 2.3.4
    cpe:2.3:a:combodo:itop:2.3.4
  • Combodo » Itop » Version: 2.4.0
    cpe:2.3:a:combodo:itop:2.4.0
  • Combodo » Itop » Version: 2.4.1
    cpe:2.3:a:combodo:itop:2.4.1
  • Combodo » Itop » Version: 2.4.2
    cpe:2.3:a:combodo:itop:2.4.2
  • Combodo » Itop » Version: 2.4.3
    cpe:2.3:a:combodo:itop:2.4.3
  • Combodo » Itop » Version: 2.5.0
    cpe:2.3:a:combodo:itop:2.5.0
  • Combodo » Itop » Version: 2.5.1
    cpe:2.3:a:combodo:itop:2.5.1
  • Combodo » Itop » Version: 2.6.0
    cpe:2.3:a:combodo:itop:2.6.0
  • Combodo » Itop » Version: 2.6.1
    cpe:2.3:a:combodo:itop:2.6.1
  • Combodo » Itop » Version: 2.6.3
    cpe:2.3:a:combodo:itop:2.6.3
  • Combodo » Itop » Version: 2.6.4
    cpe:2.3:a:combodo:itop:2.6.4
  • Combodo » Itop » Version: 2.7
    cpe:2.3:a:combodo:itop:2.7
  • Combodo » Itop » Version: 2.7.0
    cpe:2.3:a:combodo:itop:2.7.0
  • Combodo » Itop » Version: 2.7.0-1
    cpe:2.3:a:combodo:itop:2.7.0-1
  • Combodo » Itop » Version: 2.7.0-2
    cpe:2.3:a:combodo:itop:2.7.0-2
  • Combodo » Itop » Version: 2.7.1
    cpe:2.3:a:combodo:itop:2.7.1
  • Combodo » Itop » Version: 2.7.2
    cpe:2.3:a:combodo:itop:2.7.2
  • Combodo » Itop » Version: 2.7.2-1
    cpe:2.3:a:combodo:itop:2.7.2-1
  • Combodo » Itop » Version: 2.7.3
    cpe:2.3:a:combodo:itop:2.7.3
  • Combodo » Itop » Version: 2.7.3-1
    cpe:2.3:a:combodo:itop:2.7.3-1
  • Combodo » Itop » Version: 2.7.3-2
    cpe:2.3:a:combodo:itop:2.7.3-2
  • Combodo » Itop » Version: 2.7.4
    cpe:2.3:a:combodo:itop:2.7.4
  • Combodo » Itop » Version: 2.7.5
    cpe:2.3:a:combodo:itop:2.7.5
  • Combodo » Itop » Version: 2.7.5-1
    cpe:2.3:a:combodo:itop:2.7.5-1
  • Combodo » Itop » Version: 2.7.5-2
    cpe:2.3:a:combodo:itop:2.7.5-2
  • Combodo » Itop » Version: 3.0.0
    cpe:2.3:a:combodo:itop:3.0.0


Contact Us

Shodan ® - All rights reserved