CVE-2020-11696

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/06/2020
Last modified:
11/06/2020

Description

In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:combodo:itop:*:*:*:*:essential:*:*:* 2.6.4 (excluding)
cpe:2.3:a:combodo:itop:*:*:*:*:professional:*:*:* 2.6.4 (excluding)
cpe:2.3:a:combodo:itop:*:*:*:*:community:*:*:* 2.7.0 (excluding)