#VU25466 Exposed dangerous method or function in iTop - CVE-2019-11215
Published: February 19, 2020
iTop
Combodo
Description
The vulnerability allows a remote attacker to compromise the affected application.
The vulnerability exists due to usage of potential dangerous method ajax.dataloader. A remote attacker can send a specially crafted request to the application and execute arbitraty code on the server.
Successful exploitation of the vulnerability requires that configuration file is writable by the application.