CVE-2022-24780

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
GitHub_MCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
combodoitop
𝑥
< 2.7.6
combodoitop
3.0.0:alpha
combodoitop
3.0.0:beta
combodoitop
3.0.0:beta1
combodoitop
3.0.0:beta2
combodoitop
3.0.0:beta3
combodoitop
3.0.0:beta4
combodoitop
3.0.0:beta5
combodoitop
3.0.0:beta6
combodoitop
3.0.0:beta7
combodoitop
3.0.0:beta8
combodoitop
3.0.0:rc
𝑥
= Vulnerable software versions