VYPR
High severity8.0NVD Advisory· Published Apr 15, 2024· Updated Jun 17, 2026

CVE-2023-48709

CVE-2023-48709

Description

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does not prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Combodo/Itopv53 versions
    < 2.7.9+ 2 more
    • (no CPE)range: < 2.7.9
    • cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*range: <2.7.9
    • (no CPE)range: >=2.7.9, >=3.0.4, >=3.1.1, >=3.2.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.