CVE-2021-32776

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/07/2021
Last modified:
30/07/2021

Description

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* 2.7.4 (excluding)
cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.0.0:beta2:*:*:*:*:*:*