CVE-2021-21407 – Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7 …

Vuln ID: CVE-2021-21407

Published:  2021-07-21  16:15:08Z

Description: Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.

Source: NVD.NIST.GOV