CVE-2024-52000: Reflected Cross-site Scripting exploit in Combodo iTop
Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0 via systematic escaping of error messages when rendering on the page. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52000?
CVE-2024-52000 has a severity level classified as high due to its potential to allow malicious JavaScript execution.
How do I fix CVE-2024-52000?
To fix CVE-2024-52000, upgrade to Combodo iTop version 3.2.0 or later.
What is the nature of CVE-2024-52000?
CVE-2024-52000 is a reflected Cross-site Scripting (XSS) vulnerability that allows the execution of malicious scripts.
Which versions of Combodo iTop are affected by CVE-2024-52000?
CVE-2024-52000 affects all versions of Combodo iTop prior to 3.2.0.
Is user input involved in the exploitation of CVE-2024-52000?
Yes, CVE-2024-52000 can be exploited by manipulating user input in request payloads.