In Combodo iTop versions prior to 3.2.2 a high severity vulnerability CVE-2025-48055 was detected. This vulnerability allows stored cross-site scripting (XSS) in the User Portal’s browse brick, where user-supplied content could be rendered without proper sanitization. To fix this vulnerability, users should upgrade to iTop versions 3.2.2 or 3.3.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-48055.
Read more IT Business ManagementIn iTop v.3.1.0-2-11973 a high severity vulnerability CVE-2023-47489 was detected. A CSV injection in the export functionality (export-v2.php and ajax.render.php) allows a local attacker to inject crafted scripts that can lead to arbitrary code execution. To address this issue, users should upgrade iTop to versions 3.0.4, 3.1.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-47489.
Read more IT Business ManagementIn iTop v.3.1.0-2-11973 a medium severity vulnerability CVE-2023-47488 was detected. This cross-site scripting (XSS) vulnerability allows a local attacker to obtain sensitive information by injecting a crafted script into the attrib_manager_id parameter in the General Information page or the id parameter in the contact page. To address this issue, users should upgrade iTop to versions 3.0.4, 3.1.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-47488.
Read more IT Business ManagementIn Ansible Automation Platform a medium severity vulnerability CVE-2025-7738 was detected. This vulnerability allows administrators or auditors to view GitHub Enterprise authenticator client secrets in clear text via the Gateway API, increasing the risk of accidental leaks or misuse. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7738.
Read more IT Business ManagementIn Ansible versions up to 4.50.3 a medium severity vulnerability CVE-2025-53862 was detected. This vulnerability allows attackers to access three API endpoints that return verbose responses, potentially exposing sensitive information. To fix this issue, users should upgrade Ansible to version 4.52.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53862.
Read more IT Business ManagementIn Ansible version 2.x a low severity vulnerability CVE‑2025‑53861 was detected. This vulnerability allows attackers to intercept session data or hijack user sessions by exploiting insecure cookies transmitted over unencrypted connections. To fix this issue, users should upgrade Ansible to version 4.52.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53861.
Read more IT Business ManagementIn Ansible Automation Platform’s EDA component, all versions before 1.1.10 a high severity vulnerability CVE-2025-49520 was detected. This vulnerability allows attackers to execute arbitrary system commands on the EDA worker by injecting malicious arguments into the git ls-remote command, potentially leading to sensitive data exposure, such as Kubernetes or OpenShift service account tokens, and full cluster compromise. To fix this issue, users should upgrade Ansible Automation Platform’s EDA component to version 1.1.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49520.
Read more IT Business ManagementIn Ansible Automation Platform’s EDA component, all versions before 1.1.11 a high severity vulnerability CVE-2025-49521 was detected. This vulnerability allows attackers to execute arbitrary commands or access sensitive files on the system. To fix this issue, users should upgrade Ansible Automation Platform’s EDA component to version 1.1.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49521.
Read more IT Business ManagementIn iTop versions prior to 3.1.3 and 3.2.1 a medium severity vulnerability CVE-2024-56157 was detected. This vulnerability allows attackers to perform a cross-site scripting (XSS) attack by injecting malicious code into CSV content, which is executed when importing the file. To address this issue, users should upgrade iTop to versions 3.1.3 or 3.2.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-56157.
Read more IT Business Management