Impact
Combodo iTop is a web‑based IT Service Management application. Prior to release 3.2.3, the password‑reset feature returned distinguishable error messages for valid and invalid usernames, allowing an attacker to confirm the existence of accounts. This vulnerability is a classic user‑enumeration flaw, enabling an unauthenticated attacker to map valid users within the system, potentially facilitating further social‑engineering or credential‑guessing attacks.
Affected Systems
The vulnerability affects all installations of Combodo iTop versions earlier than 3.2.3. The official vendor fix was released in iTop 3.2.3, which removes the distinguishing responses during password reset. No further information about targeted OS or platform is provided.
Risk and Exploitability
The CVSS base score is 7.5, classifying the flaw as high severity. Exploitation is straightforward from a remote web interface, requiring only HTTP requests to the reset endpoint; no elevated privileges or code execution are needed. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting limited documented exploitation. Nonetheless, user enumeration is a common stepping stone for larger attacks and should be mitigated promptly.
OpenCVE Enrichment