Unrated severityNVD Advisory· Published Jul 21, 2021· Updated Aug 3, 2024
Command Injection vulnerability in the Setup Wizard
CVE-2021-21406
Description
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/Combodo/iTop/security/advisories/GHSA-pf95-6h7q-q85xmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.