Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H < 3.1.2
affected
Description
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Problem types
CWE-352: Cross-Site Request Forgery (CSRF)
Product status
References
github.com/...o/iTop/security/advisories/GHSA-8cwx-q4xh-7c7r