- Description
- Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.
- Source
- security-advisories@github.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45BBB537-3E87-4B8F-ABB1-631EA7E76797",
"versionEndIncluding": "2.7.6"
},
{
"criteria": "cpe:2.3:a:combodo:itop:3.0.0:beta:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD7E6A6A-9B1D-4BA7-9A58-ACEE1ABC46EB"
},
{
"criteria": "cpe:2.3:a:combodo:itop:3.0.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0F94E71-E468-4765-9A44-FCD9121DC414"
},
{
"criteria": "cpe:2.3:a:combodo:itop:3.0.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF68C176-A8C3-4C88-A344-74CB0E682987"
},
{
"criteria": "cpe:2.3:a:combodo:itop:3.0.0:beta3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "997A26DD-11A4-4D9F-8F6C-845068AE605C"
},
{
"criteria": "cpe:2.3:a:combodo:itop:3.0.0:beta4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06061D47-3252-4ED4-9423-600027D39551"
},
{
"criteria": "cpe:2.3:a:combodo:itop:3.0.0:beta5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5DFEEA5-6FB7-4583-A13C-B2EE74502B81"
}
],
"operator": "OR"
}
]
}
]