Unrated severityNVD Advisory· Published Nov 10, 2025· Updated Nov 10, 2025
iTop admin can drop iTop database using webhooks
CVE-2025-49145
Description
Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- github.com/Combodo/iTop/security/advisories/GHSA-55q8-mfxr-pq4jmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.