Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboar…
High CVSS 7.3
Summary
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/Combodo/iTop/commit/104dd1970f3ad828896a5092b125edb4bc1340b6
- https://github.com/Combodo/iTop/security/advisories/GHSA-gccc-8mw3-hqhp
Timeline
- nvd_ingest NVD