CVE-2021-41162
21.04.2022, 17:15
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.
Vendor | Product | Version |
---|---|---|
combodo | itop | 𝑥 ≤ 2.7.6 |
combodo | itop | 3.0.0:beta |
combodo | itop | 3.0.0:beta1 |
combodo | itop | 3.0.0:beta2 |
combodo | itop | 3.0.0:beta3 |
combodo | itop | 3.0.0:beta4 |
combodo | itop | 3.0.0:beta5 |
𝑥
= Vulnerable software versions
References