Impact
Combodo iTop, a web‑based IT service management system, contains a reflected Cross‑Site Scripting flaw triggered via the dashboard_id parameter in /pages/ajax.render.php. The vulnerability allows an attacker to inject arbitrary JavaScript that executes in the context of logged‑in users, potentially hijacking sessions, defacing the interface, or redirecting users to malicious sites. The weakness is a classic input validation issue (CWE‑79).
Affected Systems
All installations of Combodo iTop prior to version 3.2.3 are susceptible. The vulnerability was addressed and removed in version 3.2.3. Clients running older releases should verify their current version before taking remediation steps.
Risk and Exploitability
The CVSS base score of 7.3 marks the issue as a High‑severity vulnerability, indicating significant risk to confidentiality and integrity for authenticated users. EPSS is not available, so the current likelihood of exploitation cannot be quantitatively estimated, but the attacker need only supply a crafted link or exploit it via cross‑site request. The flaw is not listed in the CISA KEV catalog, suggesting no publicly released exploit yet. Nevertheless, because the attack vector is via a web‑application parameter, the potential for widespread malicious payloads remains high.
OpenCVE Enrichment