Skip to content

XSS in ajax.render.php?operation=wizard_helper in 3.0.0-beta versions

Critical
piRGoif published GHSA-w5jw-hfvp-gx95 Apr 21, 2022

Package

iTop (SourceForge)

Affected versions

3.0.0-beta*

Patched versions

>=3.0.0-beta6

Description

Impact

The in ajax.render.php?operation=wizard_helper page don't properly escape the passed parameters, allowing XSS.

Patches

Fixed in 3.0.0 (october 2021)

References

Combodo ref N°4362

Credits

Redshell (https://github.com/RedShellSec)

For more information

If you have any questions or comments about this advisory:
Email us at [email protected]

Severity

Critical

CVE ID

CVE-2021-41162

Weaknesses

No CWEs

Credits