CVE-2023-38511: iTop Dashboard editor vulnerable dashboard config file parameter
Published Apr 15, 2024
·Updated
iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.
Affected Software
3 affected components
iTop<3.0.4, <3.1.1
iTop>=3.0.0<3.0.4
iTop>=3.1.0<3.1.1
Remediation
Event History
Apr 15, 2024
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38511?
CVE-2023-38511 is considered a moderate severity vulnerability due to full path disclosure risk.
2
How do I fix CVE-2023-38511?
To fix CVE-2023-38511, upgrade to iTop version 3.0.4 or 3.1.1 or later.
3
What are the affected versions for CVE-2023-38511?
CVE-2023-38511 affects iTop versions prior to 3.0.4 and between 3.1.0 and 3.1.1.
4
What type of vulnerability is CVE-2023-38511?
CVE-2023-38511 is a full path disclosure vulnerability found in the dashboard editor of iTop.
5
Which product is impacted by CVE-2023-38511?
CVE-2023-38511 impacts the iTop IT service management platform by Combodo.