CVE-2024-52000

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Nov 8, 2024
Updated: Nov 12, 2024
CWE ID 79

Summary

CVE-2024-52000 is a newly discovered Cross-site Scripting (XSS) vulnerability affecting the Comodo iTop IT Service Management tool. The flaw allows attackers to inject malicious JavaScript code by manipulating the payload of editing requests. Successful exploitation could lead to code execution in the context of the targeted user. iTop Version 3.2.0 has addressed this threat through the systematic escaping of error messages during rendering. Users are strongly advised to upgrade as soon as possible, as there are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share