| |
Vulnerability CVE-2020-15218
Published: 2021-01-13
Description: |
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0. |
Type:
CWE-613 (Insufficient Session Expiration)
CVSS2 => (AV:N/AC:M/Au:S/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
3.5/10 |
2.9/10 |
6.8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://github.com/Combodo/iTop/security/advisories/GHSA-3m3g-86hp-5p2j
|
|
|
Copyright 2024, cxsecurity.com
|
|
|