High severity7.4NVD Advisory· Published Aug 10, 2020· Updated Jun 17, 2026
CVE-2020-12778
CVE-2020-12778
Description
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*range: <2.7.1
- cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:rc:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- github.com/Combodo/iTop/security/advisories/GHSA-8vpf-8vjh-5fcvnvdThird Party Advisory
- www.twcert.org.tw/tw/cp-132-3834-591e2-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.