CVE-2022-24811

Publication date

2022-04-05 18:35:11

Family

GitHub_M

State

PUBLISHED

Description

Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.