CVE-2023-44396 Information
Apr 16, 2024
cve
Description
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10 3.0.4 and 3.1.1.
Reference
https://github.com/Combodo/iTop/security/advisories/GHSA-gqqj-jgh6-3x35 https://github.com/Combodo/iTop/commit/9df92665e08c4bf5d4d8a5a9fe21fd3fb26fb273 https://github.com/Combodo/iTop/commit/c72cb7e70ebf469ce0ec01f5f9b524e39afe6c7f
Share on: