{"id":"CVE-2022-31403","details":"ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.","modified":"2026-03-11T00:14:32.553242Z","published":"2022-06-14T17:15:08.453Z","references":[{"type":"WEB"},{"type":"WEB","url":"https://sourceforge.net/projects/itop/"},{"type":"WEB","url":"https://www.itophub.io/"},{"type":"EVIDENCE","url":"https://github.com/IbrahimEkimIsik/CVE/blob/main/CVE-2022-31403"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/combodo/itop","events":[{"introduced":"0"},{"last_affected":"bac2918ceb3c7b3f2583eda1a9caf66841afa1cb"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"3.0.1"}]}}],"versions":["1.0.8","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.0-a","2.6.0-products","2.6.1","2.6.2","2.6.2-1","2.6.2-2","2.6.3","2.6.4","2.7.0","2.7.0-1","2.7.0-2","2.7.0-alpha1","2.7.0-beta","2.7.0-beta2","2.7.0-rc","2.7.0-rc2","2.7.1","2.7.2","2.7.2-1","2.7.3","2.7.3-1","2.7.3-2","2.7.4","2.7.5","2.7.5-1","2.7.5-2","2.7.6","3","3.0.0","3.0.0-alpha","3.0.0-beta","3.0.0-beta2","3.0.0-beta3","3.0.0-beta4","3.0.0-beta5","3.0.0-beta6","3.0.0-beta7","3.0.0-beta8","3.0.0-rc","3.0.1","3.0.1-designer-feature-lot1","N1963","N2011","N2016","N941","N941-2","itop-carbon"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-31403.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}