Medium severity5.4NVD Advisory· Published Apr 5, 2022· Updated Jun 17, 2026
CVE-2022-24811
CVE-2022-24811
Description
Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/Combodo/iTop/commit/92a9a8c65f3cbb2cd4414ca3a3b45a5754ba57b4nvdPatchThird Party Advisory
- huntr.dev/bounties/1625056478879-Combodo/iTop/nvdExploitThird Party Advisory
- github.com/Combodo/iTop/security/advisories/GHSA-67x5-mqg4-rvgcnvdThird Party Advisory
News mentions
0No linked articles in our index yet.