CVE-2024-31448: Cross-site Scripting vulnerability in link CSV import in Combodo iTop
Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can be performed when importing this content. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. Users unable to upgrade should validate CSV content before importing it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31448?
CVE-2024-31448 has a medium severity due to the potential for Cross-site Scripting (XSS) attacks.
How do I fix CVE-2024-31448?
You can fix CVE-2024-31448 by upgrading to either version 3.1.2 or 3.2.0 of Combodo iTop.
What types of attacks are associated with CVE-2024-31448?
CVE-2024-31448 is associated with Cross-site Scripting (XSS) attacks that can occur when importing malicious CSV content.
Who is affected by CVE-2024-31448?
Any users of Combodo iTop versions prior to 3.1.2 are affected by CVE-2024-31448.
What should users do if they are using an affected version of Combodo iTop?
Users should immediately upgrade to version 3.1.2 or 3.2.0 to mitigate the risks associated with CVE-2024-31448.