CVE-2020-12779: Combodo iTop - Stored XSS
Published Aug 10, 2020
·Updated
Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
Affected Software
2 affected components
iTop<2.7.0
iTop=2.7.0-beta
Remediation
Information
Update to version 2.7.1
Event History
Aug 10, 2020
CVE Published
via MITRE·02:45 AM
Data Sourced
via MITRE·02:45 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2020-12779
2
What is the severity of CVE-2020-12779?
The severity of CVE-2020-12779 is medium with a CVSS score of 5.4.
3
How does CVE-2020-12779 affect Combodo iTop?
CVE-2020-12779 affects Combodo iTop versions up to 2.7.0 and 2.7.0-beta.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-12779?
The CWE ID for CVE-2020-12779 is CWE-79.
5
How can I mitigate the CVE-2020-12779 vulnerability?
To mitigate the CVE-2020-12779 vulnerability, it is recommended to update Combodo iTop to a version higher than 2.7.0.