CVE-2022-39216

CVSS V2 None CVSS V3 None
Description
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.
Overview
  • CVE ID
  • CVE-2022-39216
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-14T16:15:10
  • Last Modified Date
  • 2023-03-19T03:56:09
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* 1 OR 2.7.8
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* 1 OR 3.0.2-1
History
Created Old Value New Value Data Type Notes
2023-04-17 06:25:39 Added to TrackCVE
2023-04-17 06:25:42 Weakness Enumeration new