← Terug naar overzicht

Combodo iTop, a web-based IT service management tool, contains a Reflected Cross-Site Scripting (XSS) vulnerability in its synchro import script. The vulnerability is identified as CVE-2026-30890 and affects all versions prior to 3.2.3. Reflected XSS vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, credential theft, or other client-side attacks. The issue has been patched and fully remediated in iTop version 3.2.3. The fix is available via a specific commit on the official Combodo iTop GitHub repository. A security advisory has also been published on GitHub under GHSA-93q9-fc8m-5gp5. Users of iTop are strongly advised to upgrade to version 3.2.3 or later to mitigate this risk.

Affected products

  • Combodo iTop

Related CVE's

  • CVE-2026-30890

Categories

  • Enterprise Applications
  • Web Technologies