First published: Fri Jun 05 2020(Updated: )
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Combodo iTop | <2.6.4 | |
Combodo iTop | <2.6.4 | |
Combodo iTop | <2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11696 is a vulnerability in Combodo iTop that allows an attacker to exploit a menu shortcut name with a stored XSS payload.
The severity of CVE-2020-11696 is medium with a CVSS score of 6.1.
The affected software versions are Combodo iTop 2.6.4 (essential and professional) and Combodo iTop 2.7.0 (community, essential, and professional).
To fix CVE-2020-11696, upgrade to the fixed versions of Combodo iTop: version 2.7.0 for community, essential, and professional, and version 2.6.4 for essential and professional.
The CWE ID for CVE-2020-11696 is CWE-79 (Cross-Site Scripting).