go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Combodo iTop - Stored XSS

TVN ID TVN-202004006
CVE ID CVE-2020-12779
CVSS 6.8 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Affected Products Combodo iTop versions prior to 2.7.0-beta2
Description Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
Solution Update to version 2.7.1
Credit 黃榆翔、蔡仲南、Tseng, Yung-Hao
Public Date 2020-08-10
Top