Unrated severityNVD Advisory· Published Mar 14, 2023· Updated Feb 25, 2025
Authenticated users of Combodo iTop can take over any account
CVE-2022-39214
Description
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/Combodo/iTop/commit/4c1df9927d1dc6b0181ee20721f93346def026fdmitrex_refsource_MISC
- github.com/Combodo/iTop/commit/bdebea62b642622ed71410b26c81e8537e6e58famitrex_refsource_MISC
- github.com/Combodo/iTop/security/advisories/GHSA-vj96-j84g-jhx4mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.