Impact
Combodo iTop, a web‑based IT service management platform, contained a reflected Cross‑Site Scripting flaw in the dashboard revert functionality. An attacker could inject malicious scripts into the page that is returned when a user reverts a dashboard view, leading to potential theft of session cookies, credential hijack, or execution of arbitrary code in the victim’s browser. The underlying weakness is CWE‑79, which allows the exploitation of improper output encoding.
Affected Systems
All installations of Combodo iTop versions prior to 3.2.3 are vulnerable. The flaw was resolved in iTop 3.2.3 and later releases.
Risk and Exploitability
The CVSS score of 8.9 indicates a high‑severity vulnerability. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, but it remains an exploitable web‑application issue. An attacker can reach the vulnerable endpoint over the network from any user interface that invokes the dashboard revert action, making remote exploitation possible without requiring privileged access. Based on the description, it is inferred that an attacker could craft a malicious URL or form that forces the dashboard revert action, thereby injecting XSS payload during normal user interaction.
OpenCVE Enrichment