Impact
User of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges.
Patches
Fixed in 2.7.6 and 3.0.0
References
Credits
Many thanks to @MarkusKrell and SCRT SA for their reports !
For more information
If you have any questions or comments about this advisory:
Email us at [email protected]
Impact
User of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges.
Patches
Fixed in 2.7.6 and 3.0.0
References
Credits
Many thanks to @MarkusKrell and SCRT SA for their reports !
For more information
If you have any questions or comments about this advisory:
Email us at [email protected]