Description
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
>= 3.0.0, < 3.1.3
>= 3.2.0, < 3.2.1
References
github.com/...o/iTop/security/advisories/GHSA-rhv2-wfrr-4j2j
github.com/...ommit/082d865efaf8a349b60fe3875e9c726c24f8a8bd
github.com/...ommit/37fc1a572380f2faa67fddea5b1a3a4ba72ed54e
github.com/...ommit/5780f26817c2303c5bdd0ad16e21d4d959780b0b