Skip to content

XSS when displaying attached HTML file

High
piRGoif published GHSA-67x5-mqg4-rvgc Apr 5, 2022

Package

iTop (Sourceforge)

Affected versions

2.6.4, 2.7.5

Patched versions

2.7.6, 3.0.0

Description

Impact

When displaying HTML attachments XSS are possible for scripts outside of script tags

Patches

Fixed in 2.7.6, 3.0.0

References

Combodo ref N°4129

Credits

@ranjit-git / Huntr

For more information

Cross-site Scripting (XSS) - Stored vulnerability found in itop

If you have any questions or comments about this advisory:
Email us at [email protected]

Severity

High

CVE ID

CVE-2022-24811

Weaknesses

No CWEs

Credits