Cross-site Scripting (XSS) - Stored in combodo/itop


Reported on

Jun 30th 2021

ūüí• BUG

stored xss via file upload


here in this case i uploaded a html file with xss payload inside.
Plz check this 1 minute video to reproduce

ūüí• Impact

I see there is many different type of role base user . So, user who has permission to upload document can make xss attack against higher level user or admin

ranjit-git modified the report
2 years ago
2 years ago


Hey ranjit-git, I've just emailed the maintainer and am waiting to hear back. Good job!

We have contacted a member of the combodo/itop team and are waiting to hear back 2 years ago
A combodo/itop maintainer validated this vulnerability 2 years ago
ranjit-git has been awarded the disclosure bounty
The fix bounty is now up for grabs
A combodo/itop maintainer
a year ago

The fix will be part of 2.7.6 that has just been released. A GitHub advisory was created :

We will publish ths page and the advusory in 3 monthes.

Pierre Goiffon marked this as fixed in 2.7.6 with commit 92a9a8 a year ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
Pierre Goiffon
a year ago

Hi, Combodo usually send goodies for its contributors, as a way to thank them. @ranjit-git can you send your postal address to pierre.goiffon @ (remove spaces around the @)?

a year ago


@mainatiner Thanks for such care. Happy to secure itop project. I will send postal address to above mail id

to join this conversation