Vulnerabilities > Combodo > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-07-21 CVE-2021-32776 Cross-Site Request Forgery (CSRF) vulnerability in Combodo Itop
Combodo iTop is a web based IT Service Management tool.
network
combodo CWE-352
6.8
2021-07-21 CVE-2021-21407 Cross-Site Request Forgery (CSRF) vulnerability in Combodo Itop
Combodo iTop is an open source, web based IT Service Management tool.
network
combodo CWE-352
4.3
2021-07-21 CVE-2021-21406 Command Injection vulnerability in Combodo Itop
Combodo iTop is an open source, web based IT Service Management tool.
network
low complexity
combodo CWE-77
6.5
2021-01-13 CVE-2020-15220 Insufficient Session Expiration vulnerability in Combodo Itop
Combodo iTop is a web based IT Service Management tool.
network
combodo CWE-613
5.8
2021-01-13 CVE-2020-15219 Information Exposure Through an Error Message vulnerability in Combodo Itop
Combodo iTop is a web based IT Service Management tool.
network
low complexity
combodo CWE-209
4.0
2021-01-12 CVE-2020-4079 Information Exposure vulnerability in Combodo Itop
Combodo iTop is a web based IT Service Management tool.
network
low complexity
combodo CWE-200
4.0
2020-08-10 CVE-2020-12780 Incorrect Authorization vulnerability in Combodo Itop
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
network
low complexity
combodo CWE-863
5.0
2020-08-10 CVE-2020-12778 Cross-site Scripting vulnerability in Combodo Itop
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
network
low complexity
combodo CWE-79
6.1
2020-06-05 CVE-2020-11696 Cross-site Scripting vulnerability in Combodo Itop
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload.
network
combodo CWE-79
4.3
2020-06-05 CVE-2020-11697 Cross-site Scripting vulnerability in Combodo Itop
In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload.
network
combodo CWE-79
4.3