Cross-site Scripting in Combodo iTop
CVE-2021-41162
9.3CRITICAL
What is CVE-2021-41162?
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the ajax.render.php?operation=wizard_helper
page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Version(s)
iTop >= 3.0.0-beta, < 3.0.0-beta6