Security Advisory

CVE-2023-48710

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-04-15 17:47:51
Last updated 2024-08-02 21:37:54
Assigner GitHub_M
State PUBLISHED

Description

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be from a third-party module. The `pages/exec.php` script as been fixed to limit execution of PHP files only. Other file types wont be retrieved and exposed. The vulnerability is fixed in 2.7.10, 3.0.4, 3.1.1, and 3.2.0.