First published: Fri Feb 14 2020(Updated: )
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Combodo iTop | <=2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13966 is a vulnerability in iTop through 2.6.0 that allows for the delivery of XSS payloads in certain fields of the XML file used to build the dashboard.
CVE-2019-13966 affects iTop versions up to and including 2.6.0.
CVE-2019-13966 has a severity rating of medium, with a CVSS score of 6.1.
An attacker can exploit CVE-2019-13966 by delivering an XSS payload in specific fields of the XML file used for building the dashboard in iTop.
Yes, you can refer to the following links for more information about CVE-2019-13966: [1] [2]
Yes, the vulnerability can be fixed by upgrading iTop to a version that is not affected.