CVE-2024-52001
Combodo
CVE-2024-52001 allows unauthorized access to sensitive IT services information within Combodo iTop. This information disclosure vulnerability impacts users of the iTop IT Service Management tool. The SVRS score of 30 suggests a low level of active threat, but upgrading is still recommended.
The vulnerability enables portal users to bypass access controls and view services information they shouldn't have access to. While the CVSS score is relatively low (4.3), the presence of the "In The Wild" tag indicates potential active exploitation. The fix is available in iTop version 3.2.0, and users are advised to upgrade to prevent potential data breaches. Although the SVRS suggests the risk isn't critical, proactive patching remains the best course of action to ensure data security and compliance.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.