First published: Mon Nov 04 2024(Updated: )
Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <2.7.9 | |
iTop | >=3.0.0<3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34443 is considered a high severity vulnerability due to its potential for Cross-site Scripting (XSS) attacks.
To fix CVE-2023-34443, upgrade to versions 2.7.9, 3.0.4, or 3.1.0 of Combodo iTop.
CVE-2023-34443 affects Combodo iTop versions prior to 2.7.9 and between 3.0.0 and 3.0.4.
CVE-2023-34443 is a Cross-site Scripting (XSS) vulnerability that can allow the execution of malicious scripts.
There are no known workarounds for CVE-2023-34443; upgrading to a safe version is strongly recommended.