CVE-2024-51995

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 284

Summary

CVE-2024-51995 affects the Combodo iTop IT Service Management tool, allowing attackers to request any route they desire as long as they specify a permitted operation. This vulnerability, which can result in unintended page dispatches, has been addressed in version 3.2.0 by implementing the same access control pattern in the `ajax.render.php` page as in `UI.php`. Users are strongly advised to upgrade to this version to mitigate the risk of potential attacks, as there are currently no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share