Home

Description

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.

PUBLISHED Reserved 2023-09-22 | Published 2024-04-15 | Updated 2024-08-02 | Assigner GitHub_M




MEDIUM: 5.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

>= 3.1.0, < 3..1.1
affected

References

github.com/...o/iTop/security/advisories/GHSA-96xm-p83r-hm97

github.com/...ommit/03c9ffc0334fd44f3f0e82477264087064e1c732

github.com/...o/iTop/security/advisories/GHSA-96xm-p83r-hm97

github.com/...ommit/03c9ffc0334fd44f3f0e82477264087064e1c732

cve.org (CVE-2023-43790)

nvd.nist.gov (CVE-2023-43790)

Download JSON