Skip to content
Noroxi

Combodo records

82 published records for vendor combodo.

All records

82 records
  • Combodo iTop's weak password reset token leads to account takeover

    CriticalCVSS 9.8No exploitEPSS 1%

    combodo · itopMar 14, 2023

  • iTop limit pages/exec.php script to PHP files

    CriticalCVSS 9.8No exploitEPSS 1%

    combodo · itopApr 15, 2024

  • Authenticated users of Combodo iTop can take over any account

    HighCVSS 7.5No exploitEPSS 26%

    combodo · itopMar 14, 2023

  • Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter

    CriticalCVSS 9.6No exploitEPSS 0%

    combodo · itopDec 13, 2024

  • Code Injection in Combodo iTop

    HighCVSS 8.8Proof of conceptEPSS 6%

    combodo · itopApr 5, 2022

  • Command Injection vulnerability in the Setup Wizard

    HighCVSS 8.8No exploitEPSS 1%

    combodo · itopJul 21, 2021

  • Cross-Site Request Forgery (CSRF) in several iTop pages

    HighCVSS 8.8Proof of conceptEPSS 1%

    combodo · itopNov 8, 2024

  • SSRF through arbitrary PHP class instantiation in the user portal in Combodo iTop

    HighCVSS 8.8No exploitEPSS 1%

    combodo · itopNov 5, 2024

  • Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request

    HighCVSS 8.8No exploitEPSS 0%

    combodo · itopAug 9, 2020

  • No CSRF form token cleanup on Windows servers

    HighCVSS 8.8No exploitEPSS 0%

    combodo · itopJul 21, 2021

  • CSRF security issue on CSV import in Combodo iTop

    HighCVSS 8.8No exploitEPSS 0%

    combodo · itopNov 4, 2024

  • iTop server vulnerable to portal code injection

    HighCVSS 8.5No exploitEPSS 1%

    combodo · itopMay 14, 2025

  • Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality

    HighCVSS 8.6No exploitEPSS 0%

    combodo · itopNov 10, 2025

  • A command injection vulnerability exists in TeemIp versions before 2.4.0.

    HighCVSS 7.2Proof of conceptEPSS 13%

    combodo · teemipApr 4, 2019

  • A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information a

    HighCVSS 8.1No exploitEPSS 1%

    combodo · itopMar 16, 2020

  • In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling

    HighCVSS 8.1No exploitEPSS 1%

    combodo · itopFeb 14, 2020

  • iTop vulnerable to potential formula injection in Excel/CSV export file

    HighCVSS 8.0No exploitEPSS 1%

    combodo · itopApr 15, 2024

  • Possible Cross-Site Request Forgery in Combodo iTop

    HighCVSS 8.1No exploitEPSS 1%

    combodo · itopApr 5, 2022

  • CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the

    HighCVSS 7.8No exploitEPSS 0%

    combodo · itopNov 9, 2023

  • Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing t

    HighCVSS 7.2No exploitEPSS 7%

    combodo · itopMay 2, 2018

  • Unauthorized setup leads to SSRF in Combodo/iTop

    HighCVSS 7.5No exploitEPSS 1%

    combodo · itopOct 19, 2021

  • iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile ope

    HighCVSS 7.5No exploitEPSS 1%

    combodo · itopFeb 14, 2020

  • Combodo iTop - Broken Access Control

    HighCVSS 7.5No exploitEPSS 1%

    combodo · itopAug 9, 2020

  • Combodo iTop - Security Misconfiguration

    HighCVSS 7.5No exploitEPSS 1%

    combodo · itopAug 9, 2020

  • CVE-2020-4079
    30Monitor

    Information disclosure vulnerability in iTop

    HighCVSS 7.7No exploitEPSS 1%

    combodo · itopJan 12, 2021