Unrated severityNVD Advisory· Published Oct 19, 2021· Updated Aug 3, 2024
Unauthorized setup leads to SSRF in Combodo/iTop
CVE-2021-32663
Description
iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/Combodo/iTop/commit/43daa2ef088bf928a2386fa19324628c3f19b807mitrex_refsource_MISC
- github.com/Combodo/iTop/commit/6be9a87c150978752bc68baae1a5c4833ddadfecmitrex_refsource_MISC
- github.com/Combodo/iTop/security/advisories/GHSA-ghqc-r8f6-q9m9mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.