First published: Fri Jun 05 2020(Updated: )
In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <2.6.4 | |
iTop | <2.6.4 | |
iTop | <2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11697 is classified as a medium severity vulnerability due to the potential for reflective XSS attacks.
To fix CVE-2020-11697, upgrade to iTop version 2.7.0 or later for the community edition or version 2.6.4 for essential and professional editions.
CVE-2020-11697 affects iTop versions prior to 2.6.4 for essential and professional editions and prior to 2.7.0 for the community edition.
CVE-2020-11697 is a reflective cross-site scripting (XSS) vulnerability.
Yes, CVE-2020-11697 is present in both the essential and professional packages of iTop prior to version 2.6.4.