Lucene search

K
cveGitHub_MCVE-2020-4079
HistoryJan 12, 2021 - 8:15 p.m.

CVE-2020-4079

2021-01-1220:15:24
CWE-200
GitHub_M
web.nvd.nist.gov
21
2
combodo itop
itsm
web-based
ajax
excel export
unauthorized access
data filtering
cve-2020-4079
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

28.4%

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the “excel export” portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.

Affected configurations

Nvd
Vulners
Node
combodoitopRange<2.7.2
OR
combodoitopMatch2.7.3
VendorProductVersionCPE
combodoitop*cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
combodoitop2.7.3cpe:2.3:a:combodo:itop:2.7.3:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "iTop",
    "vendor": "Combodo",
    "versions": [
      {
        "status": "affected",
        "version": "< 2.7.2"
      }
    ]
  }
]

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

28.4%

Related for CVE-2020-4079