CVE-2020-15218

Admin pages are cached and can be embedded

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.


We have discovered 4 live websites that are affected by CVE-2020-15218.

Run a Free Instant Scan




Affected Software

Product  Combodo iTop
Category Issue Trackers
Vulnerable Domains4 live websites (25% of Combodo iTop install base)
Vulnerable Versions
  • from 0 through 2.7.2
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-613 Insufficient Session Expiration



Details

  • Published - Jan 14, 2021
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2020-15218
Denmark1 websites
France1 websites
GB1 websites
Netherlands1 websites

Website Distribution by TLD

Number of websites using CVE-2020-15218
.com1 websites
.dk1 websites
.fr1 websites
.net1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-15218

Top websites that are affected by CVE-2020-15218. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.*****.dk Denmark**,***,***
*******.******.fr France**,***,***
******.*********.net Netherlands**,***,***
****.***************.com GB***,***,***
See full domain list

FAQ

CVE-2020-15218 is Insufficient Session Expiration in Combodo iTop
A total of 4 websites have been identified as vulnerable to CVE-2020-15218, based on global website indexing conducted by WebTechSurvey.
The Combodo iTop is affected by the CVE-2020-15218 vulnerability.
Combodo iTop versions up to 2.7.2 are vulnerable to CVE-2020-15218.
CVE-2020-15218 is resolved in version 2.7.2 of Combodo iTop.