CVE-2022-24870: Stored Cross-site Scripting in Combodo iTop
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-24870?
CVE-2022-24870 is a vulnerability in the Combodo iTop IT Service Management tool that allows for stored cross-site scripting attacks.
What is the severity of CVE-2022-24870?
The severity of CVE-2022-24870 is high, with a CVSS score of 5.4.
How does CVE-2022-24870 affect Combodo iTop?
CVE-2022-24870 affects Combodo iTop 3.0.0 beta releases prior to 3.0.0 beta3 by enabling a stored cross-site scripting attack through the customization mechanism.
How can I fix CVE-2022-24870?
To fix CVE-2022-24870, users are advised to upgrade to Combodo iTop 3.0.0 beta3 or a later version.
What is CWE-79?
CWE-79 is a category of software weaknesses that covers cross-site scripting vulnerabilities.