Vulnerability Description
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Combodo | Itop | <= 2.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/arbahayoub/POC/blob/master/itop_command_injection_1.txtExploitThird Party Advisory
- https://sourceforge.net/p/itop/tickets/1585/Issue Tracking
- https://github.com/arbahayoub/POC/blob/master/itop_command_injection_1.txtExploitThird Party Advisory
- https://sourceforge.net/p/itop/tickets/1585/Issue Tracking
FAQ
What is CVE-2018-10642?
CVE-2018-10642 is a vulnerability with a CVSS score of 7.2 (HIGH). Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-c...
How severe is CVE-2018-10642?
CVE-2018-10642 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10642?
Check the references section above for vendor advisories and patch information. Affected products include: Combodo Itop.