CVE-2024-51994: Cross-site Scripting in portal picture upload in Combodo iTop
Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (XSS) vulnerability. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51994?
CVE-2024-51994 is classified as a Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2024-51994?
To fix CVE-2024-51994, upgrade to Combodo iTop version 3.2.0 or later.
What are the affected versions of Combodo iTop related to CVE-2024-51994?
Versions of Combodo iTop prior to 3.2.0 are affected by CVE-2024-51994.
What type of vulnerability is CVE-2024-51994?
CVE-2024-51994 is a Cross-site Scripting (XSS) vulnerability that can be triggered by uploading a malicious text file.
Who should be concerned about CVE-2024-51994?
All users of affected versions of Combodo iTop should be concerned about CVE-2024-51994 and should take action to upgrade.