CVE-2023-47123: iTop vulnerable to XSS vulnerability in n:n relations "tagset" widget
Published Apr 15, 2024
·Updated
iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.
Affected Software
2 affected components
iTop<3.1.1, <3.2.0
iTop>=3.1.0<3.1.1
Remediation
Event History
Apr 15, 2024
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47123?
CVE-2023-47123 has been classified with a medium severity level due to the potential XSS attack vector.
2
How do I fix CVE-2023-47123?
To fix CVE-2023-47123, upgrade to versions 3.1.1 or 3.2.0 of Combodo iTop.
3
What type of vulnerability is CVE-2023-47123?
CVE-2023-47123 is a cross-site scripting (XSS) vulnerability.
4
What products are affected by CVE-2023-47123?
CVE-2023-47123 affects versions of Combodo iTop prior to 3.1.1 and 3.2.0.
5
What is the impact of CVE-2023-47123?
The impact of CVE-2023-47123 is that it allows malicious code injection leading to potential XSS attacks.