CVE-2021-32664: Reflected XSS in Combodo/iTop
Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-32664?
CVE-2021-32664 is a XSS vulnerability in Combodo iTop, an open source web-based IT Service Management tool, that allows attackers to execute malicious scripts on the "run query" page when logged in as an administrator.
How severe is CVE-2021-32664?
CVE-2021-32664 has a severity rating of 4.8 (High).
How can I fix CVE-2021-32664?
To fix CVE-2021-32664, update your Combodo iTop to version 2.6.5 or 2.7.5 which resolves the XSS vulnerability.
What is the affected software for CVE-2021-32664?
The affected software for CVE-2021-32664 is Combodo iTop versions up to 2.7.0.
What is the Common Weakness Enumeration (CWE) for CVE-2021-32664?
The CWE for CVE-2021-32664 is CWE-79, which stands for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').