Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-29842 | Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. |
Tue, 05 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Combodo
Combodo itop |
|
| CPEs | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Combodo
Combodo itop |
|
| Metrics |
ssvc
|
Mon, 04 Nov 2024 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | CSRF security issue on CSV import in Combodo iTop | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-05T16:27:54.054Z
Reserved: 2024-04-08T13:48:37.492Z
Link: CVE-2024-31998
Updated: 2024-11-05T16:27:49.619Z
Status : Analyzed
Published: 2024-11-05T00:15:04.083
Modified: 2024-11-06T14:31:46.643
Link: CVE-2024-31998
No data.
OpenCVE Enrichment
No data.
EUVD