VYPR

Itop

by Combodo

Source repositories

CVEs (102)

  • CVE-2020-15218MedJan 13, 2021
    risk 0.44cvss 6.8epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back button. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2020-12779MedAug 10, 2020
    risk 0.44cvss 6.8epss 0.01

    Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

  • CVE-2026-34948HigAug 21, 2026
    risk 0.43cvss 7.7epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

  • CVE-2020-4079HigJan 12, 2021
    risk 0.43cvss 7.7epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows getting data without scope filtering. This allows a user to access data they which…

  • CVE-2026-30866HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

  • CVE-2026-27490HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.

  • CVE-2026-27462HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.

  • CVE-2024-52601MedMay 14, 2025
    risk 0.42cvss 6.5epss 0.00

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix…

  • CVE-2024-56157MedMay 14, 2025
    risk 0.41cvss 6.3epss 0.00

    iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1. As a workaround, check CSV…

  • CVE-2026-30819HigAug 21, 2026
    risk 0.40cvss 7.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.

  • CVE-2024-52000MedNov 8, 2024
    risk 0.40cvss 6.1epss 0.00

    Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0…

  • CVE-2023-47488MedNov 9, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

  • CVE-2022-31403MedJun 14, 2022
    risk 0.40cvss 6.1epss 0.02

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.

  • CVE-2022-31402MedJun 10, 2022
    risk 0.40cvss 6.1epss 0.02

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

  • CVE-2020-15220MedJan 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2020-11696MedJun 5, 2020
    risk 0.40cvss 6.1epss 0.01

    In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.

  • CVE-2020-11697MedJun 5, 2020
    risk 0.40cvss 6.1epss 0.01

    In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.

  • CVE-2019-13966MedFeb 14, 2020
    risk 0.40cvss 6.1epss 0.01

    In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).

  • CVE-2019-13965MedFeb 14, 2020
    risk 0.40cvss 6.1epss 0.02

    Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the…

  • CVE-2026-30865HigAug 21, 2026
    risk 0.39cvss 7.1epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.

Page 3 of 6