CVE-2025-24026
- EPSS 0.08%
- Veröffentlicht 14.05.2025 14:59:47
- Zuletzt bearbeitet 01.08.2025 18:39:05
iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the reg...
CVE-2025-24022
- EPSS 0.25%
- Veröffentlicht 14.05.2025 14:57:37
- Zuletzt bearbeitet 16.01.2026 18:16:06
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.
- EPSS 0.06%
- Veröffentlicht 14.05.2025 14:48:42
- Zuletzt bearbeitet 22.08.2025 21:15:30
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for ...
CVE-2024-56157
- EPSS 0.06%
- Veröffentlicht 14.05.2025 14:40:46
- Zuletzt bearbeitet 01.08.2025 18:39:45
iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1...
CVE-2024-52601
- EPSS 0.07%
- Veröffentlicht 14.05.2025 14:39:15
- Zuletzt bearbeitet 01.08.2025 18:39:53
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1...
CVE-2025-27139
- EPSS 0.24%
- Veröffentlicht 25.02.2025 20:15:37
- Zuletzt bearbeitet 28.02.2025 13:35:22
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue.
CVE-2024-54139
- EPSS 0.33%
- Veröffentlicht 13.12.2024 16:15:26
- Zuletzt bearbeitet 11.03.2025 16:44:20
Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the `_table_id` parameter. Versions...
CVE-2024-52002
- EPSS 5.27%
- Veröffentlicht 08.11.2024 23:15:04
- Zuletzt bearbeitet 07.01.2025 16:43:28
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3....
CVE-2024-52001
- EPSS 0.36%
- Veröffentlicht 08.11.2024 23:15:04
- Zuletzt bearbeitet 07.01.2025 16:48:41
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known ...
CVE-2024-52000
- EPSS 0.74%
- Veröffentlicht 08.11.2024 23:15:03
- Zuletzt bearbeitet 07.01.2025 16:52:48
Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has bee...