First published: Mon Apr 15 2024(Updated: )
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <3.1.1>=3.1.1<=3.2.0 | |
iTop | >=3.1.0<3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43790 has a high severity rating due to its potential for user input manipulation and injection of malicious content.
To fix CVE-2023-43790, upgrade to iTop versions 3.1.1 or 3.2.0 or later.
iTop versions prior to 3.1.1 and between 3.1.1 and 3.2.0 are affected by CVE-2023-43790.
CVE-2023-43790 is a code injection vulnerability that allows malicious content to be injected into the friendlyname value via HTTP queries.
The vendor of the affected software for CVE-2023-43790 is Combodo.