{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "fixed": "3.0.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-beta"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-beta2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-beta3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-beta4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0-beta5"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "682c821d0ef14224b2182ea5840ae1739600bc22"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "94fdc79be58b298ff5d1215c3b6103c0b1f19fed"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "aa9ab1ace5bf85fa4150fa9b0227382ee138817d"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "007e1ded0db683e3459d70eb7665e166676a95f6"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "8e0ae67803ee0289a161552d86f78c6c71529343"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "f9fc85e763daa10cd553c983c01a3af451fa57d1"
            },
            {
              "fixed": "c8f3d23d30c018bc44189b38fa34a5fffb4edb22"
            }
          ],
          "repo": "https://github.com/combodo/itop",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue.",
  "id": "CVE-2021-41161",
  "modified": "2026-03-13T21:55:19.707721747Z",
  "published": "2022-04-21T17:15:07.557Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/Combodo/iTop/security/advisories/GHSA-788f-g6g9-f8fc"
    },
    {
      "type": "FIX",
      "url": "https://github.com/Combodo/iTop/commit/c8f3d23d30c018bc44189b38fa34a5fffb4edb22"
    }
  ],
  "related": [
    "GHSA-788f-g6g9-f8fc"
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}