Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Itop MEDIUM 6.1
CVE-2023-47626

iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed…

Fix: 3.1.1+
Fix from $1,600 2024-04-15
Itop MEDIUM 5.4
CVE-2023-45808

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In othe…

Fix: 2.7.10 / 3.0.4+
Fix from $1,600 2024-04-15
Itop MEDIUM 5.4
CVE-2023-47123

iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed …

Fix: 3.1.1+
Fix from $1,600 2024-04-15
Itop MEDIUM 5.4
CVE-2023-44396

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

Fix: 2.7.1 / 3.0.4+
Fix from $1,600 2024-04-15
Itop MEDIUM 5.4
CVE-2023-43790

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object frien…

Fix: 3.1.1+
Fix from $1,600 2024-04-15
Itop HIGH 7.8
CVE-2023-47489

CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v…

Mitigation only
Fix from $1,950 2023-11-09
Itop MEDIUM 6.1
CVE-2023-47488

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to th…

Mitigation only
Fix from $1,600 2023-11-09
Itop MEDIUM 6.1
CVE-2023-34446

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross s…

Patch available
Fix from $1,600 2023-10-25
Itop MEDIUM 6.1
CVE-2023-34447

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possi…

Fix: 3.0.4+
Fix from $1,600 2023-10-25
Itop CRITICAL 9.8
CVE-2022-39216

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated …

Fix: 2.7.8 / 3.0.2-1+
Fix from $2,300 2023-03-14
Itop HIGH 7.5
CVE-2022-39214EPSS 26%

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able …

Fix: 2.7.8 / 3.0.2-1+
Fix from $1,950 2023-03-14
Itop MEDIUM 6.1
CVE-2022-31403

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

No fix yet
Fix from $1,600 2022-06-14
Itop MEDIUM 6.1
CVE-2022-31402

ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

No fix yet
Fix from $1,600 2022-06-10
Itop MEDIUM 5.4
CVE-2022-24870

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips us…

Patch available
Fix from $1,600 2022-04-21
Itop MEDIUM 6.1
CVE-2021-41161

Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied …

Fix: 3.0.0+
Fix from $1,600 2022-04-21
Itop MEDIUM 6.1
CVE-2021-41162

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did …

Fix: after 2.7.6
Fix from $1,600 2022-04-21
Itop HIGH 8.8
CVE-2022-24780EPSS 5%

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the…

Fix: 2.7.6+
Fix from $1,950 2022-04-05
Itop MEDIUM 5.4
CVE-2022-24811

Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of sc…

Fix: 2.7.6+
Fix from $1,600 2022-04-05
Itop HIGH 8.1
CVE-2021-41245

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't…

Fix: 2.7.6+
Fix from $1,950 2022-04-05
Itop HIGH 7.5
CVE-2021-32663

iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given…

Fix: 2.6.5 / 2.7.5+
Fix from $1,950 2021-10-19
Itop HIGH 8.8
CVE-2021-32776

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows serv…

Fix: 2.7.4+
Fix from $1,950 2021-07-21
Itop MEDIUM 6.5
CVE-2021-32775

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values throug…

Fix: 2.7.4+
Fix from $1,600 2021-07-21
Itop MEDIUM 6.5
CVE-2021-21407

Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop …

Fix: 2.7.4+
Fix from $1,600 2021-07-21
Itop HIGH 8.8
CVE-2021-21406

Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the S…

Fix: 2.7.4+
Fix from $1,950 2021-07-21
Itop MEDIUM 6.8
CVE-2020-15218

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is vis…

Fix: 2.7.2+
Fix from $1,600 2021-01-13
Itop MEDIUM 6.1
CVE-2020-15220

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which …

Fix: 2.7.2+
Fix from $1,600 2021-01-13
Itop MEDIUM 5.4
CVE-2020-15221

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS ca…

Fix: 2.7.2+
Fix from $1,600 2021-01-13
Itop HIGH 7.7
CVE-2020-4079

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal…

Fix: 2.7.2+
Fix from $1,950 2021-01-12
Itop HIGH 8.8
CVE-2020-12781

Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

Fix: 2.7.1+
Fix from $1,950 2020-08-10
Itop HIGH 7.5
CVE-2020-12777

A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose syste…

Fix: 2.7.1+
Fix from $1,950 2020-08-10