CVE-2024-56157 Details
Description
iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1. As a workaround, check CSV content before importing it.
A cross-site scripting (XSS) vulnerability has been identified in iTop, a web-based IT Service Management tool, prior to versions 3.1.3 and 3.2.1. The issue arises when malicious code is inserted into a CSV file and then imported, allowing the script to execute. This vulnerability has been addressed in versions 3.1.3 and 3.2.1. Users are advised to inspect CSV content for harmful code before importing.
Users can update to iTop versions 3.1.3 or 3.2.1 to address this vulnerability. As an additional step, it is recommended to check CSV content for malicious code before importing.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Combodo/iTop/security/advisories/GHSA-6p48-74j9-977j | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| combodo itop | < 3.1.3 >= 3.2.0, < 3.2.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | Initial Analysis | [email protected] |
| May 14, 2025 | New CVE Received | [email protected] |