Impact
Combodo iTop is a web‑based IT service management tool. Prior to version 3.2.3 there is a reflected cross‑site scripting flaw in the run_query.php script that processes OQL queries entered in the testing interface. When a malicious payload is included in a crafted HTTP request, the script is reflected back in the page response and executed in the victim’s browser. This can allow the attacker to run arbitrary client‑side code within the context of the user who views the page, potentially compromising confidentiality and integrity of that user’s session and data. The vulnerability is fixed in version 3.2.3.
Affected Systems
All installations of Combodo iTop running any version earlier than 3.2.3 are affected. The flaw resides in the PHP code handling HTTP requests and is independent of the operating system or underlying platform.
Risk and Exploitability
The vulnerability has a CVSS score of 8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the vulnerability can be triggered by sending a crafted HTTP request to run_query.php; it is not limited to administrators, so any user or attacker who can send such a request could potentially exploit the flaw.
OpenCVE Enrichment