Aller au contenu

Fiche vulnérabilité

CVE-2023-48709 : faille élevée combodo itop (CVSS 8.0)

Description

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code Execution by default, uninformed users may become victims. This vulnerability is fixed in 2.7.9, 3.0.4, 3.1.1, and 3.2.0.

En bref

Sévérité
Élevée (CVSS 8.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
15 avr. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • combodo itop

Références

Rechercher une autre vulnérabilité dans la base CVE