CVE-2023-34445: Cross-site Scripting vulnerability on pages/ajax.render.php in Combodo iTop
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34445?
CVE-2023-34445 has a moderate severity level due to the potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2023-34445?
To mitigate CVE-2023-34445, upgrade to versions 2.7.9, 3.0.4, or 3.1.0 of Combodo iTop.
Which versions of Combodo iTop are affected by CVE-2023-34445?
CVE-2023-34445 affects all versions of Combodo iTop prior to 2.7.9 and between 3.0.0 and 3.0.4.
Is there a workaround for CVE-2023-34445?
There are no known workarounds for CVE-2023-34445; upgrading is the only solution.
What types of attacks are possible with CVE-2023-34445?
CVE-2023-34445 allows for XSS attacks where scripts can be executed outside of script tags.