CVE-2023-34446: iTop XSS vulnerability on pages/preferences.php
Published Oct 25, 2023
·Updated
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying pages/preferences.php, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
Affected Software
1 affected component
iTop=3.0.3
Remediation
Event History
Oct 25, 2023
CVE Published
03:35 PM
Data Sourced
03:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-34446?
The severity of CVE-2023-34446 is classified as a medium-level vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2023-34446?
To fix CVE-2023-34446, upgrade to versions 3.0.4 or 3.1.0 of the iTop platform.
3
What versions of iTop are affected by CVE-2023-34446?
CVE-2023-34446 affects iTop versions prior to 3.0.4 and 3.1.0.
4
What type of vulnerability is CVE-2023-34446?
CVE-2023-34446 is classified as a cross-site scripting (XSS) vulnerability.
5
Where was CVE-2023-34446 discovered?
CVE-2023-34446 was discovered in the pages/preferences.php file of the iTop web-based IT service management platform.