Impact
The vulnerability allows an attacker to learn the exact iTop version by inspecting the HTML title attribute of the logo on the login page. This is an information disclosure flaw that can aid attackers in tailoring subsequent exploits but does not directly compromise authorization or integrity. The flaw is identified as CWE-200 and results in a moderate confidentiality impact.
Affected Systems
All Combodo iTop installations running any version older than 3.2.3 contain the flaw. The issue is resolved in version 3.2.3 and later; therefore any deployment that has not applied that update is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk profile. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote web-based, where any unauthenticated user can view the login page and read the title attribute of the logo. Because the disclosed information is only the version number, the exploitation path is limited to reconnaissance and does not lead to immediate elevation of privileges or denial of service.
OpenCVE Enrichment