CVE-2023-44396 Information

Description

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10 3.0.4 and 3.1.1.

Reference

https://github.com/Combodo/iTop/security/advisories/GHSA-gqqj-jgh6-3x35 https://github.com/Combodo/iTop/commit/9df92665e08c4bf5d4d8a5a9fe21fd3fb26fb273 https://github.com/Combodo/iTop/commit/c72cb7e70ebf469ce0ec01f5f9b524e39afe6c7f

Share on: