iTop Platform Vulnerability: Malicious Formulas in CSV/Excel Exports May Lead to Remote Code Execution
CVE-2023-48709

8HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
15 April 2024

What is CVE-2023-48709?

The iTop IT service management platform is susceptible to a vulnerability that allows users to export data containing malicious formulas in CSV or Excel formats. When these files are opened, especially in Excel 2016, users may unwittingly execute harmful code due to lack of built-in protections against remote code execution. This flaw can compromise user systems and data integrity. Prompt updates to versions 2.7.9, 3.0.4, 3.1.1, and 3.2.0 are critical for users to safeguard against these security risks.

Affected Version(s)

iTop < 2.7.9 < 2.7.9

iTop >= 3.0.0, < 3.0.4 < 3.0.0, 3.0.4

iTop >= 3.1.0, < 3.1.1 < 3.1.0, 3.1.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.