First published: Tue Oct 19 2021(Updated: )
Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Combodo iTop | <2.6.5 | |
Combodo iTop | >=2.7.0<2.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32664 is a XSS vulnerability in Combodo iTop, an open source web-based IT Service Management tool, that allows attackers to execute malicious scripts on the "run query" page when logged in as an administrator.
CVE-2021-32664 has a severity rating of 4.8 (High).
To fix CVE-2021-32664, update your Combodo iTop to version 2.6.5 or 2.7.5 which resolves the XSS vulnerability.
The affected software for CVE-2021-32664 is Combodo iTop versions up to 2.7.0.
The CWE for CVE-2021-32664 is CWE-79, which stands for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').