CVE-2021-41161: XSS in csvimport in 3.0.0-beta versions
Published Apr 21, 2022
·Updated
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
6 affected components
iTop<3.0.0
iTop=3.0.0-beta
iTop=3.0.0-beta2
iTop=3.0.0-beta3
iTop=3.0.0-beta4
iTop=3.0.0-beta5
Remediation
Event History
Apr 21, 2022
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-41161?
CVE-2021-41161 is a vulnerability in Combodo iTop versions prior to 3.0.0-beta6 that allows for javascript injection into rendered CSV files.
2
How severe is CVE-2021-41161?
CVE-2021-41161 has a severity rating of 6.1 (Critical).
3
How can I fix CVE-2021-41161?
To fix CVE-2021-41161, users are advised to upgrade to version 3.0.0-beta6 or later of Combodo iTop.
4
Are there any known workarounds for CVE-2021-41161?
There are no known workarounds for CVE-2021-41161.
5
Where can I find more information about CVE-2021-41161?
You can find more information about CVE-2021-41161 on the official GitHub page of Combodo iTop.