CVE-2020-15218

MEDIUM

Combodo iTop <2.7.2, 3.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.0076
EPSS Percentile 50.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Details

CWE
CWE-613
Status published
Products (2)
combodo/itop 3.0.0 alpha
combodo/itop < 2.7.2
Published Jan 13, 2021
Tracked Since Feb 18, 2026