First published: Fri Jun 10 2022(Updated: )
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Combodo iTop | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-31402 is medium with a CVSS score of 6.1.
An attacker can exploit CVE-2022-31402 by injecting malicious scripts through the /itop/webservices/export-v2.php endpoint.
To fix CVE-2022-31402, users should update ITOP to a patched version that addresses the cross-site scripting vulnerability.