Combodo iTop
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*
- < 3.2.1
A vulnerability in iTop, a web-based IT Service Management tool, prior to version 3.2.1, allows portal users to view any contact's picture by altering the picture ID in the URL. This issue has been addressed in version 3.2.1.
Exploitation of this vulnerability allows a portal user to access and view pictures of other contacts without authorization.
Users can upgrade to iTop version 3.2.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.