CVE-2023-34444: Cross-site Scripting vulnerability on pages/ajax.searchform.php in Combodo iTop
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34444?
CVE-2023-34444 has a high severity level due to its potential for cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2023-34444?
To fix CVE-2023-34444, users should upgrade to Combodo iTop version 2.7.9, 3.0.4, or 3.1.0.
Which versions of Combodo iTop are affected by CVE-2023-34444?
CVE-2023-34444 affects all versions of Combodo iTop prior to 2.7.9 and between 3.0.0 to 3.0.4.
Is there a workaround for CVE-2023-34444?
No, there are currently no known workarounds for mitigating CVE-2023-34444.
What kind of attacks can CVE-2023-34444 enable?
CVE-2023-34444 can enable cross-site scripting (XSS) attacks for scripts loaded outside of script tags.