CVE-2018-10642: Code Injection
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10642?
CVE-2018-10642 is a command injection vulnerability in Combodo iTop 2.4.1.
How does CVE-2018-10642 work?
CVE-2018-10642 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration.
What is the severity of CVE-2018-10642?
The severity of CVE-2018-10642 is high with a CVSS score of 7.2.
How can CVE-2018-10642 be exploited?
CVE-2018-10642 can be exploited by exploiting the TestConfig() function in the config.php file.
Is there a patch available for CVE-2018-10642?
At the time of writing this FAQ, there is no official patch available for CVE-2018-10642. It is recommended to update to a version of Combodo iTop that is not affected by this vulnerability.