#VU25466 Exposed dangerous method or function in iTop - CVE-2019-11215

 

#VU25466 Exposed dangerous method or function in iTop - CVE-2019-11215

Published: February 19, 2020


Vulnerability identifier: #VU25466
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-11215
CWE-ID: CWE-749
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
iTop
Software vendor:
Combodo

Description

The vulnerability allows a remote attacker to compromise the affected application.

The vulnerability exists due to usage of potential dangerous method ajax.dataloader. A remote attacker can send a specially crafted request to the application and execute arbitraty code on the server.

Successful exploitation of the vulnerability requires that configuration file is writable by the application.


Remediation

Install updates from vendor's website.

External links