Impact
The flaw in LinkSetController.php permits authenticated console users to supply arbitrary class and key values, bypassing profile grants. This enables them to delete objects, clear external keys, and read attributes without permission, exposing both confidentiality and integrity. The weakness corresponds to CWE‑862 – missing authorization. An attacker only needs a valid console user session; no additional privileges are required.
Affected Systems
Combodo iTop versions 3.1.0 through 3.3.0 are affected. The product is listed as Combodo iTop; no other versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, so exploitation probability is unclear. The CVE is not in the CISA KEV catalog. Attackers must first authenticate to the console; once authenticated they can use the delete, detach, and get-remote-object routes to manipulate or read data. No public exploit is known, but the lack of proper authorization creates a significant risk for users with console privileges to cause data loss or exposure.
OpenCVE Enrichment