CVE-2021-21406

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
21/07/2021
Last modified:
30/07/2021

Description

Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* 2.7.4 (excluding)
cpe:2.3:a:combodo:itop:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:2.7.5-1:*:*:*:*:*:*:*