CNNVD-202511-909 Information
CNNVD ID
CNNVD-202511-909
Related CVE
- CNNVD Published: 2025-11-10
Description (Chinese)
Combodo iTop是法国Combodo公司的一套基于ITIL开发且用于IT环境日常运营的开源Web应用程序。该程序提供事件管理、配置管理和问题管理等功能。 Combodo iTop 2.7.13之前版本和3.2.2之前版本存在跨站脚本漏洞,该漏洞源于错误字段包含恶意内容时容易受到跨站脚本攻击。
Description (English)
Combodo iTop is an open-source Web application developed by the French company Combodo based on ITIL and used in the daily operation of the IT environment. It provides features such as incident management, configuration management and issue management. The previous version of Combodo iTop 2.7.13 and the previous version of 3.2.2 had a cross-site script loophole, which arose out of the vulnerability of the cross-site script when the wrong field contained malicious elements.
Hazard Level
Medium
Vulnerability Type
跨站脚本
Affected Vendor
Combodo
Published
2025-11-10
Last Modified
2026-02-24
References
https://github.com/Combodo/iTop/security/advisories/GHSA-292c-hgcf-2g22 https://access.redhat.com/security/cve/cve-2025-48065
Patch
https://github.com/Combodo/iTop/releases
Share on: