Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-41162
HistoryApr 21, 2022 - 4:45 p.m.

CVE-2021-41162 Cross-site Scripting in Combodo iTop

2022-04-2116:45:13
CWE-79
GitHub_M
www.cve.org
3
cve-2021-41162
combodo itop
web based
it service management
cross-site scripting
ajax.render.php
upgrade
attack vector
user supplied parameters

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

26.2%

Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the ajax.render.php?operation=wizard_helper page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.

CNA Affected

[
  {
    "product": "iTop",
    "vendor": "Combodo",
    "versions": [
      {
        "status": "affected",
        "version": ">= 3.0.0-beta, < 3.0.0-beta6"
      }
    ]
  }
]

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

26.2%

Related for CVELIST:CVE-2021-41162