Total vulnerabilities in the database
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the ajax.render.php?operation=wizard_helper
page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.
Software | From | Fixed in |
---|---|---|
combodo / itop | 3.0.0-beta | 3.0.0-beta.x |
combodo / itop | 3.0.0-beta2 | 3.0.0-beta2.x |
combodo / itop | 3.0.0-beta3 | 3.0.0-beta3.x |
combodo / itop | 3.0.0-beta4 | 3.0.0-beta4.x |
combodo / itop | 3.0.0-beta5 | 3.0.0-beta5.x |
combodo / itop | 3.0.0-beta1 | 3.0.0-beta1.x |
combodo / itop | - | 2.7.6.x |