Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-51995— Logic bug in ajax.render.php allows for bypass of 'backOffice' access control in Combodo iTop

EPSS 0.14% · P34
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-51995

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Logic bug in ajax.render.php allows for bypass of 'backOffice' access control in Combodo iTop
Source: NVD (National Vulnerability Database)
Vulnerability Description
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in `UI.php` to the `ajax.render.php` page which does not allow arbitrary `routes` to be dispatched. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Combodo iTop 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Combodo iTop是法国Combodo公司的一套基于ITIL开发且用于IT环境日常运营的开源Web应用程序。该程序提供事件管理、配置管理和问题管理等功能。 Combodo iTop 3.2之前版本存在访问控制错误漏洞,该漏洞源于访问控制逻辑不一致,导致攻击者可获取敏感信息或执行非授权的操作。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CombodoiTop < 3.2.0 -

II. Public POCs for CVE-2024-51995

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-51995

登录查看更多情报信息。

Same Patch Batch · Combodo · 2024-11-07 · 3 CVEs total

CVE-2024-51994Cross-site Scripting in portal picture upload in Combodo iTop
CVE-2024-51993Password is stored in clear in the database in Combodo iTop

IV. Related Vulnerabilities

V. Comments for CVE-2024-51995

No comments yet


Leave a comment