CVE-2024-51995
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 284
Summary
CVE-2024-51995 affects the Combodo iTop IT Service Management tool, allowing attackers to request any route they desire as long as they specify a permitted operation. This vulnerability, which can result in unintended page dispatches, has been addressed in version 3.2.0 by implementing the same access control pattern in the `ajax.render.php` page as in `UI.php`. Users are strongly advised to upgrade to this version to mitigate the risk of potential attacks, as there are currently no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Combodo iTop
Affected Vendors
- Combodo