Exposed dangerous method or function in iTop - CVE-2019-11215

 

Exposed dangerous method or function in iTop - CVE-2019-11215

Published: February 19, 2020


Vulnerability identifier: #VU25466
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-11215
CWE-ID: CWE-749
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Combodo
Affected software:
iTop

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise the affected application.

The vulnerability exists due to usage of potential dangerous method ajax.dataloader. A remote attacker can send a specially crafted request to the application and execute arbitraty code on the server.

Successful exploitation of the vulnerability requires that configuration file is writable by the application.


How to mitigate CVE-2019-11215

Install updates from vendor's website.

Sources