Combodo iTop
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*
- < 2.7.12
- < 3.1.3
- < 3.2.1
A vulnerability allowing server-side code execution has been identified in iTop, a web-based IT Service Management tool. This issue affects versions prior to 2.7.12, 3.1.3, and 3.2.1. The vulnerability arises from a code injection in the portal's frontend, which could be exploited to execute arbitrary code on the iTop server.
Exploitation of this vulnerability allows for arbitrary code execution on the server where iTop is hosted.
Users can upgrade to iTop versions 2.7.12, 3.1.3, or 3.2.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.