← Terug naar overzicht

Combodo iTop, a web-based IT service management tool, was found vulnerable to Reflected Cross-Site Scripting (XSS) in its dashboard revert functionality. The vulnerability is tracked as CVE-2026-30864 and affects versions prior to 3.2.3. Reflected XSS attacks occur when malicious scripts are injected into a web application and reflected back to the user's browser, potentially allowing attackers to steal session tokens, credentials, or perform actions on behalf of victims. The issue has been patched in iTop version 3.2.3. Organizations using iTop should upgrade immediately to the fixed version to mitigate risk. The advisory was published on both NVD and GitHub Security Advisories.

Affected products

  • Combodo iTop

Related CVE's

  • CVE-2026-30864

Categories

  • Enterprise Applications
  • Web Technologies