Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-51739 PoC — Combodo iTop 信息泄露漏洞

Source
Associated Vulnerability
Title:Combodo iTop 信息泄露漏洞 (CVE-2024-51739)
Description:Combodo iTop是法国Combodo公司的一套基于ITIL开发且用于IT环境日常运营的开源Web应用程序。该程序提供事件管理、配置管理和问题管理等功能。 Combodo iTop 2.7.11之前版本、3.0.5之前版本、3.1.2之前版本和3.2.0之前版本存在信息泄露漏洞,该漏洞源于未经身份验证的用户可以执行用户枚举,以便暴力破解有效帐户。
Description
From the webservices/rest.php file, several operations are accessible from an unauthenticated user. One of them is `do_reset_pwd`, allowing to reset a user password. This feature can be abused to perform user enumeration when a non-existent user is provided.
File Snapshot

id: CVE-2024-51739 info: name: iTop - User Enumeration via REST Endpoint author: DhiyaneshDk ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.