Security Advisory

CVE-2023-34445

8.8
HIGH

Vulnerability Description

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Published Date November 5, 2024
Official Source NIST NVD Advisory