Combodo iTop
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*
- >= 3, < 3.2.2
A vulnerability allowing insecure direct object reference (IDOR) has been identified in Combodo iTop versions 3.x prior to 3.2.2. This vulnerability allows users with a Service Desk Agent profile to create a ModuleInstallation object, which they should not be authorized to do.
Exploitation of this vulnerability allows users to create ModuleInstallation objects without proper authorization, potentially leading to unauthorized changes or additions within the iTop application.
Users can upgrade to iTop version 3.2.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.