Skip to content

Stored XSS in menu shortcut title

High
steffunky published GHSA-4h6p-jghj-8qxm Jun 5, 2020

Package

No package listed

Affected versions

< 2.6.4, < 2.7.0

Patched versions

2.6.4, 2.7.0

Description

Impact

The shortcut title is not sanitized correctly, and could be used for XSS injection.

Patches

  • 2.6.4 : packages essential, professional
  • 2.7.0 : packages community, essential, professional

Credits

Many thanks to TheNerdOne for his report !

References

Combodo ref N°2853
https://sourceforge.net/p/itop/tickets/1846/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11696

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

High

CVE ID

CVE-2020-11696

Weaknesses

No CWEs