CVE-2024-51994
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-51994 is a recently identified Cross-Site Scripting (XSS) vulnerability affecting the Combodo iTop IT Service Management tool. In affected versions, uploading a specially crafted text file containing JavaScript code to the portal triggers the vulnerability. This issue could allow attackers to inject malicious scripts into a user's browser and steal sensitive data or take control of their session. The vulnerability has been addressed in version 3.2.0, and all users are strongly advised to upgrade as soon as possible. There are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Combodo iTop
Affected Vendors
- Combodo