Vulnerability CVE-2022-39214


Published: 2023-03-14

Description:
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

Type:

CWE-863

(Incorrect Authorization)

 References:
https://github.com/Combodo/iTop/commit/bdebea62b642622ed71410b26c81e8537e6e58fa
https://github.com/Combodo/iTop/security/advisories/GHSA-vj96-j84g-jhx4
https://github.com/Combodo/iTop/commit/4c1df9927d1dc6b0181ee20721f93346def026fd

Copyright 2026, cxsecurity.com

 

Back to Top