Vulnerabilities
Vulnerable Software
Combodo:  >> Itop  >> 3.0.2  Security Vulnerabilities
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.
CVSS Score
6.8
EPSS Score
0.009
Published
2024-04-15
iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.
CVSS Score
5.0
EPSS Score
0.005
Published
2024-04-15
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
CVSS Score
8.8
EPSS Score
0.012
Published
2023-10-25
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.
CVSS Score
9.6
EPSS Score
0.022
Published
2023-03-14
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.
CVSS Score
7.4
EPSS Score
0.002
Published
2023-03-14


Contact Us

Shodan ® - All rights reserved