Vulnerabilities > Combodo > Itop > 2.4.3

DATE CVE VULNERABILITY TITLE RISK
2020-02-14 CVE-2019-13965 Cross-site Scripting vulnerability in Combodo Itop
Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php.
network
low complexity
combodo CWE-79
6.1