VYPR

Itop

by Combodo

Source repositories

CVEs (102)

  • CVE-2024-32870MedNov 5, 2024
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to…

  • CVE-2021-21406MedJul 21, 2021
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

  • CVE-2020-12781MedAug 10, 2020
    risk 0.37cvss 5.7epss 0.00

    Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

  • CVE-2026-34949MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions. This issue has been fixed in version…

  • CVE-2026-34836MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.

  • CVE-2024-51994MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will trigger an Cross-site Scripting (XSS) vulnerability. This issue has been addressed in version 3.2.0 and all users are advised to…

  • CVE-2025-24026MedMay 14, 2025
    risk 0.34cvss 5.3epss 0.00

    iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a…

  • CVE-2025-24969MedMay 14, 2025
    risk 0.33cvss 5.0epss 0.00

    iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

  • CVE-2015-6544MedFeb 20, 2018
    risk 0.33cvss 6.1epss 0.05

    Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

  • CVE-2025-48878MedNov 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version…

  • CVE-2025-24785MedMay 14, 2025
    risk 0.28cvss 4.3epss 0.00

    iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided…

  • CVE-2024-52001MedNov 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this…

  • CVE-2024-51740MedNov 5, 2024
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user. The user portal form manager has been fixed to only instantiate classes derived from it. This issue has…

  • CVE-2020-15219MedJan 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7.2 and 3.0.0.

  • CVE-2026-27463MedAug 21, 2026
    risk 0.27cvss 5.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.

  • CVE-2024-51993LowNov 7, 2024
    risk 0.22cvss 3.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised…

  • CVE-2026-33047MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.

  • CVE-2026-33333LowAug 21, 2026
    risk 0.16cvss 3.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

  • CVE-2011-4275Nov 26, 2011
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted…

  • CVE-2022-39214CriMar 14, 2023
    risk 0.02cvss 9.6epss 0.26

    Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

Page 4 of 6