Combodo

Itop

102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 24.08.2026 18:57:55
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

  • EPSS 0.2%
  • Veröffentlicht 24.08.2026 18:52:43
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

  • EPSS 0.35%
  • Veröffentlicht 24.08.2026 18:50:48
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing wr...

  • EPSS 0.23%
  • Veröffentlicht 21.08.2026 23:16:24
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

  • EPSS 0.22%
  • Veröffentlicht 21.08.2026 23:16:24
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions. This issue h...

  • EPSS 0.2%
  • Veröffentlicht 21.08.2026 22:16:37
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

  • EPSS 0.45%
  • Veröffentlicht 21.08.2026 22:16:37
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environmen...

  • EPSS 0.28%
  • Veröffentlicht 21.08.2026 22:16:37
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.

  • EPSS 0.27%
  • Veröffentlicht 21.08.2026 22:16:36
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.

  • EPSS 0.22%
  • Veröffentlicht 21.08.2026 22:16:36
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.