Description
iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-51265 | iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0. |
References
History
Thu, 06 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Combodo
Combodo itop |
|
| CPEs | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Combodo
Combodo itop |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T21:01:22.830Z
Reserved: 2023-10-30T19:57:51.676Z
Link: CVE-2023-47123
Updated: 2024-08-02T21:01:22.830Z
Status : Analyzed
Published: 2024-04-15T18:15:08.327
Modified: 2025-02-06T20:59:58.567
Link: CVE-2023-47123
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD