CVE-2024-31998: CSRF security issue on CSV import in Combodo iTop
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31998?
CVE-2024-31998 is a critical security vulnerability due to its potential for Cross-Site Request Forgery (CSRF), which can lead to unauthorized actions in Combodo iTop.
How do I fix CVE-2024-31998?
To fix CVE-2024-31998, upgrade Combodo iTop to version 3.1.2 or later as all older versions are vulnerable.
What systems are affected by CVE-2024-31998?
CVE-2024-31998 affects all versions of Combodo iTop prior to version 3.1.2.
Is there a workaround for CVE-2024-31998?
There are no known workarounds for CVE-2024-31998, so upgrading is the recommended solution.
What type of vulnerability is CVE-2024-31998?
CVE-2024-31998 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions.