Lucene search

K
vulnrichmentGitHub_MVULNRICHMENT:CVE-2023-34446
HistoryOct 25, 2023 - 3:35 p.m.

CVE-2023-34446 iTop XSS vulnerability on pages/preferences.php

2023-10-2515:35:21
CWE-79
GitHub_M
github.com
2
cve-2023-34446
itop
xss
vulnerability
pages/preferences.php
cross site scripting
open source
it service management platform
versions 3.0.4
versions 3.1.0

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

20.2%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying pages/preferences.php, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*"
    ],
    "vendor": "combodo",
    "product": "itop",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "3.0.4",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

20.2%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-34446