Описание
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.7.9 (исключая)Версия от 3.0.0 (включая) до 3.0.4 (исключая)
Одно из
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00635
Низкий
8.8 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79
EPSS
Процентиль: 70%
0.00635
Низкий
8.8 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79