VYPR

Vendor CVEs

Combodo

All CVEs

103 total · sorted by risk
  • CVE-2021-32664HigOct 19, 2021
    risk 0.00cvss 8.1epss 0.01

    Combodo iTop is an open source web based IT Service Management tool. In affected versions there is a XSS vulnerability on "run query" page when logged as administrator. This has been resolved in versions 2.6.5 and 2.7.5.

  • CVE-2021-32663HigOct 19, 2021
    risk 0.00cvss 8.7epss 0.01

    iTop is an open source web based IT Service Management tool. In affected versions an attacker can call the system setup without authentication. Given specific parameters this can lead to SSRF. This issue has been resolved in versions 2.6.5 and 2.7.5 and later

  • CVE-2013-0805Mar 20, 2014
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to…

Page 3 of 3