CSV Import Vulnerability Affects iTop, Upgrade to 3.1.2 or 3.2.0 Advised
CVE-2024-31998

8.8HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
5 November 2024

What is CVE-2024-31998?

A vulnerability exists in Combodo iTop, an IT Service Management tool, where a Cross-Site Request Forgery (CSRF) can be executed during the CSV import simulation process. This vulnerability affects the functionality and security of the application, making it crucial for users to upgrade to the latest versions, 3.1.2 and 3.2.0, as there are no known workarounds to mitigate its impact. The security of affected users relies on prompt updates to these versions to prevent potential exploitation.

Affected Version(s)

iTop < 3.1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.