CVE-2023-48710: iTop limit pages/exec.php script to PHP files
iTop is an IT service management platform. Files from the env-production folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be from a third-party module. The pages/exec.php script as been fixed to limit execution of PHP files only. Other file types won't be retrieved and exposed. The vulnerability is fixed in 2.7.10, 3.0.4, 3.1.1, and 3.2.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48710?
CVE-2023-48710 has a medium severity due to the potential unauthorized access to sensitive files.
How do I fix CVE-2023-48710?
To fix CVE-2023-48710, ensure proper access controls are implemented for the `env-production` folder.
Which versions of iTop are affected by CVE-2023-48710?
CVE-2023-48710 affects iTop versions up to 2.7.10 and 3.0.4, including versions 3.1.0 to 3.1.1, and 3.2.0.
What type of vulnerability is CVE-2023-48710?
CVE-2023-48710 is an unauthorized file retrieval vulnerability.
Can third-party modules be affected by CVE-2023-48710?
Yes, if sensitive files from third-party modules are stored in the `env-production` folder, they may be at risk due to CVE-2023-48710.