Lucene search

K
cveGitHub_MCVE-2021-41162
HistoryApr 21, 2022 - 5:15 p.m.

CVE-2021-41162

2022-04-2117:15:07
CWE-79
GitHub_M
web.nvd.nist.gov
55
combodo itop
it service management
xss
cross site scripting
security vulnerability
cve-2021-41162
upgrade advisory

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

26.2%

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the ajax.render.php?operation=wizard_helper page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.

Affected configurations

Nvd
Vulners
Node
combodoitopRange2.7.6
OR
combodoitopMatch3.0.0beta
OR
combodoitopMatch3.0.0beta1
OR
combodoitopMatch3.0.0beta2
OR
combodoitopMatch3.0.0beta3
OR
combodoitopMatch3.0.0beta4
OR
combodoitopMatch3.0.0beta5
VendorProductVersionCPE
combodoitop*cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
combodoitop3.0.0cpe:2.3:a:combodo:itop:3.0.0:beta:*:*:*:*:*:*
combodoitop3.0.0cpe:2.3:a:combodo:itop:3.0.0:beta1:*:*:*:*:*:*
combodoitop3.0.0cpe:2.3:a:combodo:itop:3.0.0:beta2:*:*:*:*:*:*
combodoitop3.0.0cpe:2.3:a:combodo:itop:3.0.0:beta3:*:*:*:*:*:*
combodoitop3.0.0cpe:2.3:a:combodo:itop:3.0.0:beta4:*:*:*:*:*:*
combodoitop3.0.0cpe:2.3:a:combodo:itop:3.0.0:beta5:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "iTop",
    "vendor": "Combodo",
    "versions": [
      {
        "status": "affected",
        "version": ">= 3.0.0-beta, < 3.0.0-beta6"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

26.2%

Related for CVE-2021-41162