VYPR
Medium severity6.1NVD Advisory· Published Jan 13, 2021· Updated Jun 17, 2026

CVE-2020-15220

CVE-2020-15220

Description

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

Affected products

4
  • Combodo/Itop4 versions
    cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*range: <2.7.2
    • cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*
    • (no CPE)range: <2.7.2, <3.0.0
    • (no CPE)range: < 2.7.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.