CVE-2023-43790: iTop vulnerable to XSS in friendlyname in object details
Published Apr 15, 2024
·Updated
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.
Affected Software
2 affected components
iTop<3.1.1, >=3.1.1<=3.2.0
iTop>=3.1.0<3.1.1
Remediation
Event History
Apr 15, 2024
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-43790?
CVE-2023-43790 has a high severity rating due to its potential for user input manipulation and injection of malicious content.
2
How do I fix CVE-2023-43790?
To fix CVE-2023-43790, upgrade to iTop versions 3.1.1 or 3.2.0 or later.
3
What versions of iTop are affected by CVE-2023-43790?
iTop versions prior to 3.1.1 and between 3.1.1 and 3.2.0 are affected by CVE-2023-43790.
4
What type of vulnerability is CVE-2023-43790?
CVE-2023-43790 is a code injection vulnerability that allows malicious content to be injected into the friendlyname value via HTTP queries.
5
Who is the vendor of the affected software for CVE-2023-43790?
The vendor of the affected software for CVE-2023-43790 is Combodo.