We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
A user that have enough rights to create webhooks (mostly administrator) can drop database.
Will be fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
Combodo N°8316 - [SECU] iTop admin can drop iTop database using webhooks
Thanks to Dennis Lassiter
Impact
A user that have enough rights to create webhooks (mostly administrator) can drop database.
Patches
Will be fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
References
Combodo N°8316 - [SECU] iTop admin can drop iTop database using webhooks
Credits
Thanks to Dennis Lassiter