First published: Thu Nov 09 2023(Updated: )
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=3.1.0-2-11973 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47488 is a Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973.
CVE-2023-47488 allows a local attacker to obtain sensitive information via a crafted script to specific parameters in Combodo iTop v.3.1.0-2-11973.
The severity of CVE-2023-47488 is medium with a CVSS score of 6.1.
To fix CVE-2023-47488, it is recommended to update Combodo iTop to a version that has addressed the vulnerability.
You can find more information about CVE-2023-47488 at https://bugplorer.github.io/cve-xss-itop/