Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which they should not have access to. This is fixed in versions 2.7.2 and 3.0.0.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-01-12T19:20:14

Updated: 2021-01-12T19:20:14

Reserved: 2019-12-30T00:00:00


Link: CVE-2020-4079

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-01-12T20:15:24.760

Modified: 2021-01-14T17:26:36.357


Link: CVE-2020-4079

JSON object: View

cve-icon Redhat Information

No data.

CWE