First published: Wed Jan 13 2021(Updated: )
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Combodo iTop | <2.7.2 | |
Combodo iTop | =3.0.0-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Combodo iTop is a web based IT Service Management tool.
The vulnerability in Combodo iTop is an XSS (Cross-site Scripting) vulnerability.
Versions 2.7.2 and 3.0.0-alpha of Combodo iTop are affected by the vulnerability.
By modifying the target browser local storage, an attacker can generate an XSS in the iTop console breadcrumb.
Yes, the vulnerability has been fixed in versions 2.7.2 and 3.0.0 of Combodo iTop.