First published: Mon Nov 04 2024(Updated: )
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
iTop | <3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31998 is a critical security vulnerability due to its potential for Cross-Site Request Forgery (CSRF), which can lead to unauthorized actions in Combodo iTop.
To fix CVE-2024-31998, upgrade Combodo iTop to version 3.1.2 or later as all older versions are vulnerable.
CVE-2024-31998 affects all versions of Combodo iTop prior to version 3.1.2.
There are no known workarounds for CVE-2024-31998, so upgrading is the recommended solution.
CVE-2024-31998 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions.