First published: Mon Apr 15 2024(Updated: )
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <2.7.10<3.0.4<3.1.1 | |
iTop | <2.7.1 | |
iTop | >=3.0.0<3.0.4 | |
iTop | >=3.1.0<3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44396 is classified as a Cross-Site Scripting (XSS) vulnerability.
To remediate CVE-2023-44396, update iTop to version 2.7.10, 3.0.4, or 3.1.1.
Versions of iTop prior to 2.7.10, 3.0.4, and 3.1.1 are affected by CVE-2023-44396.
An attacker exploiting CVE-2023-44396 can execute arbitrary JavaScript code in the context of a user's browser session.
Currently, there is no official workaround for CVE-2023-44396; updating to a fixed version is recommended.