CVE-2023-47123
CVSS V2 None
CVSS V3 None
Description
iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when this object will displayed as an n:n relation item in another object. This vulnerability is fixed in 3.1.1 and 3.2.0.
Overview
- CVE ID
- CVE-2023-47123
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-15T17:31:21.407Z
- Last Modified Date
- 2024-06-04T17:26:44.001Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/Combodo/iTop/security/advisories/GHSA-mx8x-693w-9hjp | x_refsource_CONFIRM |
https://github.com/Combodo/iTop/commit/34ba4fa0ce99534f751d9f170fe0eda103e20c72 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-47123 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47123 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 09:21:56 | Added to TrackCVE |