Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Itop HIGH 7.5
CVE-2020-12780

A security misconfiguration exists in Combodo iTop, which can expose sensitive information.

Fix: 2.7.1+
Fix from $1,950 2020-08-10
Itop MEDIUM 6.1
CVE-2020-12778

Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.

Fix: 2.7.1+
Fix from $1,600 2020-08-10
Itop MEDIUM 5.4
CVE-2020-12779

Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

Fix: 2.7.0+
Fix from $1,600 2020-08-10
Itop MEDIUM 6.1
CVE-2020-11696

In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, profession…

Fix: 2.6.4 / 2.7.0+
Fix from $1,600 2020-06-05
Itop MEDIUM 6.1
CVE-2020-11697

In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional…

Fix: 2.6.4 / 2.7.0+
Fix from $1,600 2020-06-05
Itop HIGH 8.1
CVE-2019-19821

A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information and modify…

Fix: 2.7+
Fix from $1,950 2020-03-16
Itop HIGH 7.5
CVE-2019-13967

iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. T…

Fix: after 2.6.0
Fix from $1,950 2020-02-14
Itop MEDIUM 6.1
CVE-2019-13965

Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to w…

Fix: after 2.6.0
Fix from $1,600 2020-02-14
Itop MEDIUM 6.1
CVE-2019-13966

In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar …

Fix: after 2.6.0
Fix from $1,600 2020-02-14
Itop HIGH 8.1
CVE-2019-11215

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.data…

Fix: after 2.6.0
Fix from $1,950 2020-02-14
Teemip HIGH 7.2
CVE-2019-10863EPSS 13%

A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wi…

Fix: 2.4.0+
Fix from $1,950 2019-04-04
Itop HIGH 7.2
CVE-2018-10642EPSS 7%

Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platfo…

Fix: after 2.4.1
Fix from $1,950 2018-05-02
Itop MEDIUM 6.1
CVE-2015-6544EPSS 5%

Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject a…

Fix: 2.2.0-2459+
Fix from $1,600 2018-02-20