{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T23:19:59.953","vulnerabilities":[{"cve":{"id":"CVE-2020-15218","sourceIdentifier":"security-advisories@github.com","published":"2021-01-13T17:15:12.460","lastModified":"2026-06-17T02:56:17.557","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0."},{"lang":"es","value":"Combodo iTop es una herramienta de Administración de Servicios de TI basada en web.&#xa0;En iTop versiones anteriores a 2.7.2 y 3.0.0, las páginas de administración son almacenadas en caché, por lo que su contenido es visible después de la desconexión usando el botón de retroceso del navegador.&#xa0;Esto es corregido en las versiones 2.7.2 y 3.0.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Combodo","product":"iTop","versions":[{"version":"< 2.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*","versionEndExcluding":"2.7.2","matchCriteriaId":"812ABDA6-D405-4617-8A76-47F606E43D38"},{"vulnerable":true,"criteria":"cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*","matchCriteriaId":"608F63C6-0F54-47D8-BFD5-FB5511BDB548"}]}]}],"references":[{"url":"https://github.com/Combodo/iTop/security/advisories/GHSA-3m3g-86hp-5p2j","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/Combodo/iTop/security/advisories/GHSA-3m3g-86hp-5p2j","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}