Unrated severityNVD Advisory· Published Jul 21, 2021· Updated Aug 3, 2024
Portal : the CSRF token isn't validated
CVE-2021-21407
Description
Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/Combodo/iTop/security/advisories/GHSA-9wq8-4qm9-3j6fmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.