Medium severity6.1NVD Advisory· Published Jun 5, 2020· Updated Jun 17, 2026
CVE-2020-11696
CVE-2020-11696
Description
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Combodo/iTopdescription
cpe:2.3:a:combodo:itop:*:*:*:*:essential:*:*:*+ 3 more
- cpe:2.3:a:combodo:itop:*:*:*:*:essential:*:*:*range: <2.6.4
- cpe:2.3:a:combodo:itop:*:*:*:*:professional:*:*:*range: <2.6.4
- cpe:2.3:a:combodo:itop:*:*:*:*:community:*:*:*range: <2.7.0
- (no CPE)range: up to 2.7.0 (community, essential, professional) and up to 2.6.4 (essential, professional)
- Range: up to 2.6.4
- Range: up to 2.7.0
Patches
Vulnerability mechanics
References
2- github.com/Combodo/iTop/security/advisories/GHSA-4h6p-jghj-8qxmnvdThird Party Advisory
- www.itophub.io/wiki/pagenvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.