Skip to content

XSS vulnerability in dashlet refresh

High
Molkobain published GHSA-q9cm-q7fc-frxh Apr 15, 2024

Package

iTop (Sourceforge)

Affected versions

3.0.3, 3.1.0

Patched versions

3.0.4, 3.1.1, 3.2.0

Description

Impact

When dashlet are refreshed, XSS attacks are possible

Patches

Fixed in 3.0.4, 3.1.1

References

Combodo ref N°6908

Severity

High
8.8
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE ID

CVE-2023-47622

Weaknesses

No CWEs

Credits