Описание
Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can be performed when importing this content. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. Users unable to upgrade should validate CSV content before importing it.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.2 (исключая)
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00829
Низкий
8.8 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 74%
0.00829
Низкий
8.8 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79