CVE-2023-34445 Information

Description

Combodo iTop is a simple web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9 3.0.4 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Reference

https://github.com/Combodo/iTop/security/advisories/GHSA-mm45-wh68-jpvq

Share on: