Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-47626 iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed… Itop 3.1.1+ Fix from $1,6002024-04-15 MEDIUM 5.4 CVE-2023-45808 iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In othe… Itop 2.7.10 / 3.0.4+ Fix from $1,6002024-04-15 MEDIUM 5.4 CVE-2023-47123 iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed … Itop 3.1.1+ Fix from $1,6002024-04-15 MEDIUM 5.4 CVE-2023-44396 iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1. Itop 2.7.1 / 3.0.4+ Fix from $1,6002024-04-15 MEDIUM 5.4 CVE-2023-43790 iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object frien… Itop 3.1.1+ Fix from $1,6002024-04-15 HIGH 7.8 CVE-2023-47489 CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v… Itop Mitigation only Fix from $1,9502023-11-09 MEDIUM 6.1 CVE-2023-47488 Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to th… Itop Mitigation only Fix from $1,6002023-11-09 MEDIUM 6.1 CVE-2023-34446 iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross s… Itop Patch available Fix from $1,6002023-10-25 MEDIUM 6.1 CVE-2023-34447 iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possi… Itop 3.0.4+ Fix from $1,6002023-10-25 CRITICAL 9.8 CVE-2022-39216 Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated … Itop 2.7.8 / 3.0.2-1+ Fix from $2,3002023-03-14 HIGH 7.5 CVE-2022-39214EPSS 26% Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able … Itop 2.7.8 / 3.0.2-1+ Fix from $1,9502023-03-14 MEDIUM 6.1 CVE-2022-31403 ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php. Itop No fix yet Fix from $1,6002022-06-14 MEDIUM 6.1 CVE-2022-31402 ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php. Itop No fix yet Fix from $1,6002022-06-10 MEDIUM 5.4 CVE-2022-24870 Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips us… Itop Patch available Fix from $1,6002022-04-21 MEDIUM 6.1 CVE-2021-41161 Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied … Itop 3.0.0+ Fix from $1,6002022-04-21 MEDIUM 6.1 CVE-2021-41162 Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did … Itop after 2.7.6 Fix from $1,6002022-04-21 HIGH 8.8 CVE-2022-24780EPSS 5% Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the… Itop 2.7.6+ Fix from $1,9502022-04-05 MEDIUM 5.4 CVE-2022-24811 Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of sc… Itop 2.7.6+ Fix from $1,6002022-04-05 HIGH 8.1 CVE-2021-41245 Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't… Itop 2.7.6+ Fix from $1,9502022-04-05 HIGH 7.5 CVE-2021-32663 iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given… Itop 2.6.5 / 2.7.5+ Fix from $1,9502021-10-19 HIGH 8.8 CVE-2021-32776 Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows serv… Itop 2.7.4+ Fix from $1,9502021-07-21 MEDIUM 6.5 CVE-2021-32775 Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values throug… Itop 2.7.4+ Fix from $1,6002021-07-21 MEDIUM 6.5 CVE-2021-21407 Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop … Itop 2.7.4+ Fix from $1,6002021-07-21 HIGH 8.8 CVE-2021-21406 Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the S… Itop 2.7.4+ Fix from $1,9502021-07-21 MEDIUM 6.8 CVE-2020-15218 Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is vis… Itop 2.7.2+ Fix from $1,6002021-01-13 MEDIUM 6.1 CVE-2020-15220 Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which … Itop 2.7.2+ Fix from $1,6002021-01-13 MEDIUM 5.4 CVE-2020-15221 Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS ca… Itop 2.7.2+ Fix from $1,6002021-01-13 HIGH 7.7 CVE-2020-4079 Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal… Itop 2.7.2+ Fix from $1,9502021-01-12 HIGH 8.8 CVE-2020-12781 Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery. Itop 2.7.1+ Fix from $1,9502020-08-10 HIGH 7.5 CVE-2020-12777 A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose syste… Itop 2.7.1+ Fix from $1,9502020-08-10