CVE-2020-15218

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*

History

15 Jan 2021, 15:14

Type Values Removed Values Added
References (CONFIRM) https://github.com/Combodo/iTop/security/advisories/GHSA-3m3g-86hp-5p2j - (CONFIRM) https://github.com/Combodo/iTop/security/advisories/GHSA-3m3g-86hp-5p2j - Third Party Advisory
CPE cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 6.8

13 Jan 2021, 18:37

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-13 17:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-15218

Mitre link : CVE-2020-15218

CVE.ORG link : CVE-2020-15218


JSON object : View

Products Affected

combodo

  • itop
CWE
CWE-613

Insufficient Session Expiration