Skip to content

XSS in the breadcrumbs

Moderate
piRGoif published GHSA-w6g2-p7pf-7hvw Jan 12, 2021

Package

No package listed

Affected versions

< 2.7.2, < 3.0.0

Patched versions

2.7.2, 3.0.0

Description

Impact

By modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb.

Patches

Fixed in 2.7.2 and 3.0.0

Credits

Many thanks to Cyblex Technologies (Clément Speybrouck, Antoine Vacher) for this report !

References

Combodo ref N°3332

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

Moderate

CVE ID

CVE-2020-15221

Weaknesses

No CWEs

Credits