Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the ajax.render.php?operation=wizard_helper page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this issue.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.7.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta4"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta5"
}
]
}