Skip to content

CSRF possible when using privUITransactionFile implementation

High
piRGoif published GHSA-33pr-5776-9jqf Apr 5, 2022

Package

No package listed

Affected versions

2.6.4, 2.7.5

Patched versions

2.7.6, 3.0.0

Description

Impact

CSRF tokens generated by privUITransactionFile aren't properly checked.

Workaround

Use the session implementation by adding in the iTop config file :

   'transaction_storage' => 'Session',

Patches

Fixed in 2.7.6, 3.0.0

References

Combodo ref N°4289

Credits

@amammad / Huntr

For more information

huntr: Cross-Site Request Forgery (CSRF) PHP Vulnerability in itop

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

High

CVE ID

CVE-2021-41245

Weaknesses

No CWEs

Credits