HIGH
CSRF security issue on CSV import in Combodo iTop
Published Nov 4, 2024
8.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
-
- Version < 3.1.2StatusaffectedConstraints-
- Version
-
- Version 0StatusaffectedConstraints<3.1.2
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://github.com/Combodo/iTop/security/advisories/GHSA-8cwx-q4xh-7c7r x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Combodo/iTop/security/advisories/GHSA-8cwx-q4xh-7c7r | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 4, 2024
Updated Nov 5, 2024
Reserved Apr 8, 2024
Link CVE-2024-31998
CISA Vulnrichment
Updated Nov 5, 2024