In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.itophub.io/wiki/page?id=2_7_0%3Arelease%3A2_7_whats_new | release notes vendor advisory |
https://github.com/Combodo/iTop/security/advisories/GHSA-xfh9-5632-hxmv | third party advisory |