Impact
An administrator can, by editing the configuration of the iTop instance, execute code on the server.
Patches
Escape and check the config parameter before executing a command based on it.
References
- Combodo N°8379 - Remote Code Execution in the backup creation functionality
Credits
Thanks to Maksim Ilyin (Positive Technologies)
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com
Impact
An administrator can, by editing the configuration of the iTop instance, execute code on the server.
Patches
Escape and check the config parameter before executing a command based on it.
References
Credits
Thanks to Maksim Ilyin (Positive Technologies)
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com