VYPR

Itop

by Combodo

Source repositories

CVEs (81)

  • CVE-2020-11696MedJun 5, 2020
    risk 0.40cvss 6.1epss 0.01

    In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, professional) in version 2.7.0 and iTop essential and iTop professional in version 2.6.4.

  • CVE-2020-11697MedJun 5, 2020
    risk 0.40cvss 6.1epss 0.01

    In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional) for version 2.7.0 and in iTop essential and iTop professional packages for version 2.6.4.

  • CVE-2019-13966MedFeb 14, 2020
    risk 0.40cvss 6.1epss 0.01

    In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).

  • CVE-2019-13965MedFeb 14, 2020
    risk 0.40cvss 6.1epss 0.02

    Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the…

  • CVE-2024-32870MedNov 5, 2024
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to…

  • CVE-2021-21406MedJul 21, 2021
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

  • CVE-2020-12781MedAug 10, 2020
    risk 0.37cvss 5.7epss 0.00

    Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

  • CVE-2024-51994MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (XSS) vulnerability. This issue has been addressed in version 3.2.0 and all users are advised to…

  • CVE-2025-24026MedMay 14, 2025
    risk 0.34cvss 5.3epss 0.00

    iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a…

  • CVE-2025-24969MedMay 14, 2025
    risk 0.33cvss 5.0epss 0.00

    iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

  • CVE-2015-6544MedFeb 20, 2018
    risk 0.33cvss 6.1epss 0.05

    Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

  • CVE-2025-48878MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version…

  • CVE-2025-24785MedMay 14, 2025
    risk 0.28cvss 4.3epss 0.00

    iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided…

  • CVE-2024-52001MedNov 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this…

  • CVE-2024-51740MedNov 5, 2024
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manager has been fixed to only instantiate classes derived from it. This issue has…

  • CVE-2020-15219MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2024-51993LowNov 7, 2024
    risk 0.22cvss 3.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised…

  • CVE-2011-4275Nov 26, 2011
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted…

  • CVE-2022-39214CriMar 14, 2023
    risk 0.02cvss 9.6epss 0.26

    Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

  • CVE-2025-24022HigMay 14, 2025
    risk 0.00cvss 8.5epss 0.01

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.