Cross-site Scripting (XSS) - Stored in combodo/itop


Reported on

Jun 30th 2021

ūüí• BUG

stored xss via file upload


here in this case i uploaded a html file with xss payload inside.
Plz check this 1 minute video to reproduce

ūüí• Impact

I see there is many different type of role base user . So, user who has permission to upload document can make xss attack against higher level user or admin

ranjit-git modified the report
a year ago
a year ago


Hey ranjit-git, I've just emailed the maintainer and am waiting to hear back. Good job!

We have contacted a member of the combodo/itop team and are waiting to hear back a year ago
A combodo/itop maintainer validated this vulnerability 6 months ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
A combodo/itop maintainer
5 months ago


The fix will be part of 2.7.6 that has just been released. A GitHub advisory was created :

We will publish ths page and the advusory in 3 monthes.

Pierre Goiffon confirmed that a fix has been merged on 92a9a8 2 months ago
The fix bounty has been dropped
Pierre Goiffon
2 months ago


Hi, Combodo usually send goodies for its contributors, as a way to thank them. @ranjit-git can you send your postal address to pierre.goiffon @ (remove spaces around the @)?

2 months ago


@mainatiner Thanks for such care. Happy to secure itop project. I will send postal address to above mail id

to join this conversation