CVE-2020-15221: XSS in the breadcrumbs
Published Jan 13, 2021
·Updated
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.
Affected Software
2 affected components
iTop<2.7.2
iTop=3.0.0-alpha
Event History
Jan 13, 2021
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is Combodo iTop?
Combodo iTop is a web based IT Service Management tool.
2
What is the vulnerability in Combodo iTop?
The vulnerability in Combodo iTop is an XSS (Cross-site Scripting) vulnerability.
3
What versions of Combodo iTop are affected by the vulnerability?
Versions 2.7.2 and 3.0.0-alpha of Combodo iTop are affected by the vulnerability.
4
How can an attacker exploit the vulnerability?
By modifying the target browser local storage, an attacker can generate an XSS in the iTop console breadcrumb.
5
Has the vulnerability been fixed?
Yes, the vulnerability has been fixed in versions 2.7.2 and 3.0.0 of Combodo iTop.