Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39216


Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.


Published

2023-03-14T16:15:10.377

Last Modified

2024-11-21T07:17:48.450

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-330

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application combodo itop < 2.7.8 Yes
Application combodo itop < 3.0.2-1 Yes

References