CVE-2024-52002: Cross-Site Request Forgery (CSRF) in several iTop pages
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52002?
CVE-2024-52002 is classified as a moderate severity vulnerability due to the potential impact of Cross-Site Request Forgery (CSRF) attacks.
How do I fix CVE-2024-52002?
To fix CVE-2024-52002, upgrade to Combodo iTop version 3.2.0 or later.
What are the consequences of exploiting CVE-2024-52002?
Exploiting CVE-2024-52002 could allow an attacker to perform unauthorized actions on behalf of logged-in users.
Which versions of Combodo iTop are affected by CVE-2024-52002?
CVE-2024-52002 affects all versions of Combodo iTop prior to version 3.2.0.
Is there a workaround for CVE-2024-52002 if I cannot upgrade?
There is no official workaround for CVE-2024-52002, so it is strongly recommended to upgrade as soon as possible.