CVE-2023-44396: Combodo Itop
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.
Affected products
- Combodo Itop: before 2.7.1 (fixed in 2.7.1); from 3.0.0, before 3.0.4 (fixed in 3.0.4); from 3.1.0, before 3.1.1 (fixed in 3.1.1)
Published 2024-04-15. Last modified 2026-06-17.