Vulnerabilities
Vulnerable Software
Combodo:  >> Itop  >> 2.7.5-1  Security Vulnerabilities
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-04-05
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.
CVSS Score
5.8
EPSS Score
0.006
Published
2021-07-21


Contact Us

Shodan ® - All rights reserved