Vulnerability Description
iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1. As a workaround, check CSV content before importing it.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Combodo | Itop | < 3.1.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-56157?
CVE-2024-56157 is a vulnerability with a CVSS score of 6.3 (MEDIUM). iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this conte...
How severe is CVE-2024-56157?
CVE-2024-56157 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-56157?
Check the references section above for vendor advisories and patch information. Affected products include: Combodo Itop.