Skip to content

Portal code injection using the formmanager_data field

Critical
piRGoif published GHSA-v97m-wgxq-rh54 Apr 5, 2022

Package

iTop (SourceForge)

Affected versions

<2.7.6, <3.0.0

Patched versions

2.7.6, 3.0.0

Description

Impact

User of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges.

Patches

Fixed in 2.7.6 and 3.0.0

References

Credits

Many thanks to @MarkusKrell and SCRT SA for their reports !

For more information

If you have any questions or comments about this advisory:
Email us at [email protected]

Severity

Critical

CVE ID

CVE-2022-24780

Weaknesses

No CWEs

Credits