High severity8.8NVD Advisory· Published Apr 5, 2022· Updated Jun 17, 2026
CVE-2022-24780
CVE-2022-24780
Description
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*range: <2.7.6
- cpe:2.3:a:combodo:itop:3.0.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:beta:*:*:*:*:*:*
- cpe:2.3:a:combodo:itop:3.0.0:rc:*:*:*:*:*:*
- (no CPE)range: <2.7.6, <3.0.0
- (no CPE)range: < 2.7.6
Patches
Vulnerability mechanics
References
6- github.com/Combodo/iTop/commit/93f273a28778e5da8e51096f021d2dc1adbf4ef3nvdPatchThird Party Advisory
- github.com/Combodo/iTop/commit/b6fac4b411b8d145fc30fa35c66b51243eafd06bnvdPatchThird Party Advisory
- github.com/Combodo/iTop/commit/eb2a615bd28100442c7f6171707bb40884af2305nvdPatchThird Party Advisory
- packetstormsecurity.com/files/167236/iTop-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- markus-krell.de/itop-template-injection-inside-customer-portal/nvdExploitThird Party Advisory
- github.com/Combodo/iTop/security/advisories/GHSA-v97m-wgxq-rh54nvdThird Party Advisory
News mentions
0No linked articles in our index yet.