CVE-2023-47626: iTop vulnerable to XSS vulnerability in authent-token
Published Apr 15, 2024
·Updated
iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.
Affected Software
2 affected components
Combodo iTop>=3.1.0<3.1.1
iTop iTop<3.1.1
Event History
Apr 15, 2024
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47626?
The severity of CVE-2023-47626 is classified as a high-risk vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2023-47626?
To fix CVE-2023-47626, upgrade iTop to version 3.1.1 or later.
3
What type of vulnerability is CVE-2023-47626?
CVE-2023-47626 is an XSS (Cross-Site Scripting) vulnerability affecting iTop's user personal tokens.
4
Which versions of iTop are affected by CVE-2023-47626?
Versions prior to 3.1.1 of iTop are affected by CVE-2023-47626.
5
Can CVE-2023-47626 lead to data breaches?
Yes, if exploited, CVE-2023-47626 can lead to unauthorized access and potential data breaches due to XSS.