| CVE-2025-48055 |
BDSA-2025-20663 |
Medium |
Nov 10, 2025 |
Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cro
more...
Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0.
less...
|
2.7.13, 3.2.1, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.2.0, 3.0.4, 2.7.10, 2.7.9
|
| CVE-2025-24969 |
BDSA-2025-4176 |
Medium |
May 14, 2025 |
iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in
more...
iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.2.0, 3.0.4, 2.7.10, 2.7.9, 3.1.0
|
| CVE-2025-24026 |
BDSA-2025-4174 |
Medium |
May 14, 2025 |
iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under
more...
iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a workaround, if iTop app_root_url is defined in the configuration file, then there is no possible way to exploit this ReDoS.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.2.0, 3.0.4, 2.7.10, 2.7.9, 3.1.0
|
| CVE-2024-56157 |
BDSA-2025-4171 |
Medium |
May 14, 2025 |
iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting
more...
iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1. As a workaround, check CSV content before importing it.
less...
|
2.7.13, 2.7.12, 3.1.2, 2.7.11, 3.2.0, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3
|
| CVE-2024-52002 |
BDSA-2024-8443 |
High |
Nov 08, 2024 |
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability.
more...
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3
|
| CVE-2024-52001 |
BDSA-2024-8448 |
Medium |
Nov 08, 2024 |
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. Th
more...
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3
|
| CVE-2024-52000 |
BDSA-2024-8439 |
Medium |
Nov 08, 2024 |
Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way
more...
Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0 via systematic escaping of error messages when rendering on the page. All users are advised to upgrade. There are no known workarounds for this vulnerability.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3
|
| CVE-2024-51995 |
BDSA-2024-8330 |
High |
Nov 07, 2024 |
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowe
more...
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in `UI.php` to the `ajax.render.php` page which does not allow arbitrary `routes` to be dispatched. All users are advised to upgrade. There are no known workarounds for this vulnerability.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3
|
| CVE-2024-51993 |
BDSA-2024-8493 |
Low |
Nov 07, 2024 |
Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured U
more...
Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised to encrypt their backups independently of the iTop application.
### Patches
Sanitize parameter
### References
N°7631 - Password is stored in clear in the database.
less...
|
2.7.13, 3.1.3, 2.7.12, 3.1.2, 2.7.11, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3
|
| CVE-2024-31998 |
BDSA-2024-8102 |
High |
Nov 05, 2024 |
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions
more...
Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versions 3.1.2 and 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
less...
|
2.7.13, 2.7.12, 2.7.11, 3.0.4, 2.7.10, 2.7.9, 3.1.0, 3.0.3, 2.7.8, 3.0.2
|