← Terug naar overzicht

Combodo iTop, a web-based IT service management tool, contains a Reflected Cross-Site Scripting (XSS) vulnerability in its universal search functionality. The vulnerability affects all versions prior to 3.2.3. Reflected XSS vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, credential theft, or other client-side attacks. The issue has been patched and resolved in version 3.2.3. A fix was committed to the official GitHub repository. A security advisory was also published via GitHub Security Advisories. Users are advised to upgrade to version 3.2.3 or later to mitigate the risk.

Affected products

  • Combodo iTop

Related CVE's

  • CVE-2026-31880

Categories

  • Enterprise Applications
  • Web Technologies