CVE-2024-52000
CVSS 3.0 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-52000 is a newly discovered Cross-site Scripting (XSS) vulnerability affecting the Comodo iTop IT Service Management tool. The flaw allows attackers to inject malicious JavaScript code by manipulating the payload of editing requests. Successful exploitation could lead to code execution in the context of the targeted user. iTop Version 3.2.0 has addressed this threat through the systematic escaping of error messages during rendering. Users are strongly advised to upgrade as soon as possible, as there are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Combodo iTop
Affected Vendors
- Combodo