Vulnerability Description
iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Combodo | Itop | >= 3.0.0, < 3.0.4 |
Related Weaknesses (CWE)
References
- https://github.com/Combodo/iTop/commit/343e87a8d4fc8253fd81aeaf0dcc424b9dc4eda7Patch
- https://github.com/Combodo/iTop/commit/89145593ef2e077529a6f7ee7cde712db637e1abPatch
- https://github.com/Combodo/iTop/security/advisories/GHSA-323r-chx5-m9gmVendor Advisory
- https://www.synacktiv.com/advisories/file-read-in-itopExploitThird Party Advisory
- https://github.com/Combodo/iTop/commit/343e87a8d4fc8253fd81aeaf0dcc424b9dc4eda7Patch
- https://github.com/Combodo/iTop/commit/89145593ef2e077529a6f7ee7cde712db637e1abPatch
- https://github.com/Combodo/iTop/security/advisories/GHSA-323r-chx5-m9gmVendor Advisory
- https://www.synacktiv.com/advisories/file-read-in-itopExploitThird Party Advisory
FAQ
What is CVE-2023-38511?
CVE-2023-38511 is a vulnerability with a CVSS score of 5.0 (MEDIUM). iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.
How severe is CVE-2023-38511?
CVE-2023-38511 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38511?
Check the references section above for vendor advisories and patch information. Affected products include: Combodo Itop.