Known CVE
iTop - User Enumeration via REST Endpoint
From the webservices/rest.php file, several operations are accessible from an unauthenticated user. One of them is `do_reset_pwd`, allowing to reset a user password. This feature can be abused to perform user enumeration when a non-existent user is provided.
CVE-2024-51739
Medium2024CVSS 5.3CWE-200
cve2024 · itop · enum · unauth · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website