iTop Platform Vulnerability: Malicious Formulas in CSV/Excel Exports May Lead to Remote Code Execution
CVE-2023-48709
8HIGH
What is CVE-2023-48709?
The iTop IT service management platform is susceptible to a vulnerability that allows users to export data containing malicious formulas in CSV or Excel formats. When these files are opened, especially in Excel 2016, users may unwittingly execute harmful code due to lack of built-in protections against remote code execution. This flaw can compromise user systems and data integrity. Prompt updates to versions 2.7.9, 3.0.4, 3.1.1, and 3.2.0 are critical for users to safeguard against these security risks.
Affected Version(s)
iTop < 2.7.9 < 2.7.9
iTop >= 3.0.0, < 3.0.4 < 3.0.0, 3.0.4
iTop >= 3.1.0, < 3.1.1 < 3.1.0, 3.1.1