iTop IT Service Management Platform Vulnerability
CVE-2023-47622

6.1MEDIUM

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
15 April 2024

What is CVE-2023-47622?

iTop, developed by Combodo, has a vulnerability that allows for cross-site scripting (XSS) attacks when the platform's dashlets are refreshed. This security flaw could enable attackers to execute malicious scripts in the context of the user’s session. The issue has been addressed in the updates 3.0.4 and 3.1.1, making it crucial for users to upgrade to these versions to ensure the security of their IT management environments.

Affected Version(s)

iTop < 3.0.4 < 3.0.4

iTop >= 3.1.0, < 3.1.1 < 3.1.0, 3.1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.