Combodo iTop, a web-based IT service management tool, contains a reflected Cross-Site Scripting (XSS) vulnerability prior to version 3.2.3. The vulnerability exists in the dashboard revert functionality, specifically through the 'dashboard_id' parameter in the '/pages/ajax.render.php' endpoint. An attacker could exploit this flaw to inject malicious scripts that execute in the context of a victim's browser. The issue has been assigned CVE-2026-30819 and is documented in the NVD. A fix has been released in iTop version 3.2.3. The patch is available via a GitHub commit and a corresponding security advisory has been published on GitHub. Users are strongly advised to upgrade to version 3.2.3 or later to mitigate the risk.