CVE-2024-54139: Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter
Published Dec 13, 2024
·Updated
Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the tableid parameter. Versions 2.7.11, 3.1.2, and 3.2.0 contain a patch for the issue.
Affected Software
8 affected components
iTop<2.7.11, <3.1.2, <3.2.0
iTop<2.7.11
iTop>=3.0.0<3.1.2
iTop=3.2.0-alpha1
iTop=3.2.0-beta1
iTop=3.2.0-rc1
iTop=3.2.0-rc2
iTop=3.2.0-rc3
Event History
Dec 13, 2024
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54139?
CVE-2024-54139 has a moderate severity rating due to its potential for cross-site scripting and request forgery.
2
How do I fix CVE-2024-54139?
To fix CVE-2024-54139, update to Combodo iTop version 2.7.11, 3.1.2, or 3.2.0 or later.
3
Which versions of Combodo iTop are affected by CVE-2024-54139?
CVE-2024-54139 affects Combodo iTop versions prior to 2.7.11, 3.1.2, and 3.2.0.
4
What type of vulnerability is CVE-2024-54139?
CVE-2024-54139 is classified as a cross-site scripting vulnerability.
5
Can CVE-2024-54139 lead to another type of attack?
Yes, CVE-2024-54139 can potentially lead to cross-site request forgery attacks.