CVE-2022-24811: Cross-site Scripting in Combodo iTop
Published Apr 5, 2022
·Updated
Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Affected Software
1 affected component
iTop<2.7.6
Remediation
Event History
Apr 5, 2022
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-24811?
CVE-2022-24811 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2022-24811?
To fix CVE-2022-24811, upgrade to Combodo iTop version 2.7.6 or later.
3
What type of vulnerability is CVE-2022-24811?
CVE-2022-24811 is a cross-site scripting (XSS) vulnerability affecting certain versions of Combodo iTop.
4
Which versions of Combodo iTop are affected by CVE-2022-24811?
CVE-2022-24811 affects Combodo iTop versions prior to 2.7.6.
5
Are there any known workarounds for CVE-2022-24811?
There are currently no known workarounds for CVE-2022-24811; upgrading is recommended.