Unrated severityNVD Advisory· Published Feb 25, 2025· Updated Feb 25, 2025
Combodo iTop vulnerable to stored self Cross-site Scripting in preferences
CVE-2025-27139
Description
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/Combodo/iTop/security/advisories/GHSA-c6mg-9537-c8cfmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.