Cross-Site Scripting Vulnerability in iTop IT Service Management Tool
CVE-2024-56157

6.3MEDIUM

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
14 May 2025

What is CVE-2024-56157?

A cross-site scripting vulnerability exists in the iTop IT Service Management tool prior to versions 3.1.3 and 3.2.1. Attackers can exploit this vulnerability by injecting malicious code into a CSV file. When this compromised CSV content is imported, it can execute malicious scripts in the context of the user's browser. This can lead to unauthorized access to sensitive information. Users are strongly advised to upgrade to versions 3.1.3 or 3.2.1, and in the meantime, thoroughly review CSV content prior to importing.

Affected Version(s)

iTop < 3.1.3 < 3.1.3

iTop >= 3.2.0, < 3.2.1 < 3.2.0, 3.2.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.