Required CVE Record Information
Description
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
9.6 | CRITICAL | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- github.com: https://github.com/Combodo/iTop/security/advisories/GHSA-vj96-j84g-jhx4 x_transferred
- github.com: https://github.com/Combodo/iTop/commit/4c1df9927d1dc6b0181ee20721f93346def026fd x_transferred
- github.com: https://github.com/Combodo/iTop/commit/bdebea62b642622ed71410b26c81e8537e6e58fa x_transferred