Cross-Site Scripting Vulnerability in iTop IT Service Management Tool
CVE-2024-56157
6.3MEDIUM
What is CVE-2024-56157?
A cross-site scripting vulnerability exists in the iTop IT Service Management tool prior to versions 3.1.3 and 3.2.1. Attackers can exploit this vulnerability by injecting malicious code into a CSV file. When this compromised CSV content is imported, it can execute malicious scripts in the context of the user's browser. This can lead to unauthorized access to sensitive information. Users are strongly advised to upgrade to versions 3.1.3 or 3.2.1, and in the meantime, thoroughly review CSV content prior to importing.
Affected Version(s)
iTop < 3.1.3 < 3.1.3
iTop >= 3.2.0, < 3.2.1 < 3.2.0, 3.2.1