HIGH
Possible Cross-Site Request Forgery in Combodo iTop
Published Apr 5, 2022
8.1
HIGHCVSS 3.1
EPSS 0.70%
Description
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file.
Affected products
-
- Version < 2.7.6StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/Combodo/iTop/commit/7757f1f2d2330d49a3ebb40194f5ec4c8eaf8186 x_refsource_MISCPatchThird Party Advisory
- https://github.com/Combodo/iTop/security/advisories/GHSA-33pr-5776-9jqf x_refsource_CONFIRMMitigationThird Party Advisory
- https://huntr.dev/bounties/0a39630d-f4b9-4468-86d8-aea3b02f91ae x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Combodo/iTop/commit/7757f1f2d2330d49a3ebb40194f5ec4c8eaf8186 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/Combodo/iTop/security/advisories/GHSA-33pr-5776-9jqf | x_refsource_CONFIRMMitigationThird Party Advisory | |
| https://huntr.dev/bounties/0a39630d-f4b9-4468-86d8-aea3b02f91ae | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 5, 2022
Updated Apr 22, 2025
Reserved Sep 15, 2021
Link CVE-2021-41245
CISA Vulnrichment
Updated Apr 22, 2025