logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-24780

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-24780

Description:
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
Last updated date:
10/07/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/19/2022
Reference url to background

https://markus-krell.de/itop-template-injection-inside-customer-portal/

Type:
exploit
Confidence:
HIGH
Date of publishing:
09/02/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/07/2022
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy