First published: Mon Apr 15 2024(Updated: )
iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <3.1.1<3.2.0 | |
iTop | >=3.1.0<3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47123 has been classified with a medium severity level due to the potential XSS attack vector.
To fix CVE-2023-47123, upgrade to versions 3.1.1 or 3.2.0 of Combodo iTop.
CVE-2023-47123 is a cross-site scripting (XSS) vulnerability.
CVE-2023-47123 affects versions of Combodo iTop prior to 3.1.1 and 3.2.0.
The impact of CVE-2023-47123 is that it allows malicious code injection leading to potential XSS attacks.