XSS in csvimport in 3.0.0-beta versions
CVE-2021-41161

9.3CRITICAL

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
21 April 2022

What is CVE-2021-41161?

Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue.

Affected Version(s)

iTop < 3.0.0-beta6

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.