iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 14 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue. | |
Title | iTop portal Insecure Direct Object Reference vulnerability | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-14T14:39:15.120Z
Updated: 2025-05-14T14:49:38.783Z
Reserved: 2024-11-14T15:05:46.770Z
Link: CVE-2024-52601

Updated: 2025-05-14T14:49:32.555Z

Status : Received
Published: 2025-05-14T15:15:55.200
Modified: 2025-05-14T15:15:55.200
Link: CVE-2024-52601

No data.