Itop
by Combodo
Source repositories
CVEs (102)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-33240 | Hig | 0.50 | 8.8 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3. | ||
| CVE-2026-31936 | Hig | 0.50 | 8.8 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3. | ||
| CVE-2021-32775 | Hig | 0.50 | 7.7 | 0.01 | Jul 21, 2021 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0. | ||
| CVE-2026-34741 | Hig | 0.49 | 8.6 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed… | ||
| CVE-2024-51739 | Hig | 0.49 | 7.5 | 0.01 | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This… | ||
| CVE-2020-12780 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2020 | A security misconfiguration exists in Combodo iTop, which can expose sensitive information. | ||
| CVE-2020-12777 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2020 | A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information. | ||
| CVE-2019-13967 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2020 | iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI.… | ||
| CVE-2020-12778 | Hig | 0.48 | 7.4 | 0.01 | Aug 10, 2020 | Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack. | ||
| CVE-2025-47286 | Hig | 0.47 | 7.2 | 0.00 | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a… | ||
| CVE-2018-10642 | Hig | 0.47 | 7.2 | 0.06 | May 2, 2018 | Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the… | ||
| CVE-2025-64167 | Hig | 0.46 | 7.1 | 0.00 | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which was deprecated. They use… | ||
| CVE-2024-51995 | Hig | 0.46 | 7.1 | 0.00 | Nov 7, 2024 | Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in `UI.php` to the… | ||
| CVE-2026-31880 | Hig | 0.45 | 8.0 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3. | ||
| CVE-2026-31803 | Hig | 0.45 | 8.0 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3. | ||
| CVE-2026-30890 | Hig | 0.45 | 8.0 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3. | ||
| CVE-2026-30826 | Hig | 0.45 | 8.0 | 0.00 | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3. | ||
| CVE-2025-27139 | Med | 0.44 | 6.8 | 0.00 | Feb 25, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue. | ||
| CVE-2021-32776 | Med | 0.44 | 6.8 | 0.00 | Jul 21, 2021 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0. | ||
| CVE-2020-15221 | Med | 0.44 | 6.8 | 0.01 | Jan 13, 2021 | Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0. |
- risk 0.50cvss 8.8epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
- risk 0.50cvss 8.8epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.
- risk 0.50cvss 7.7epss 0.01
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.
- risk 0.49cvss 8.6epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed…
- risk 0.49cvss 7.5epss 0.01
Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This…
- risk 0.49cvss 7.5epss 0.01
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
- risk 0.49cvss 7.5epss 0.01
A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.
- risk 0.49cvss 7.5epss 0.01
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI.…
- risk 0.48cvss 7.4epss 0.01
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
- risk 0.47cvss 7.2epss 0.00
Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a…
- risk 0.47cvss 7.2epss 0.06
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the…
- risk 0.46cvss 7.1epss 0.00
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which was deprecated. They use…
- risk 0.46cvss 7.1epss 0.00
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allowed. This issue has been addressed in version 3.2.0 by applying the same access control pattern as in `UI.php` to the…
- risk 0.45cvss 8.0epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.
- risk 0.45cvss 8.0epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.
- risk 0.45cvss 8.0epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.
- risk 0.45cvss 8.0epss 0.00
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.
- risk 0.44cvss 6.8epss 0.00
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue.
- risk 0.44cvss 6.8epss 0.00
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.
- risk 0.44cvss 6.8epss 0.01
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. This is fixed in versions 2.7.2 and 3.0.0.
Page 2 of 6