Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.
Published: 2026-08-21
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Combodo iTop, a web‑based IT service management tool, had a reflected Cross‑Site Scripting flaw in the dashboard save function prior to version 3.2.3. The vulnerability allows an attacker to inject arbitrary JavaScript into the page that is presented to a user when a dashboard is saved or viewed. If an attacker can supply a crafted dashboard title or other field that is reflected back in the response, the malicious script could steal session cookies, deface the interface, or perform other client‑side attacks, compromising confidentiality and integrity for the victim’s session.

Affected Systems

All installations of Combodo iTop older than version 3.2.3 are affected, regardless of service attachment. The flaw was fixed in the 3.2.3 release, so anyone running iTop prior to that should consider upgrading.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1. An exploit does not require any special privileges beyond the ability to access the dashboard save endpoint, which may require an authenticated session. As a reflected XSS, the attack would affect only the victim’s browser, but its impact can lead to credential theft or defacement. EPSS data is not available and the issue is not listed in the CISA KEV catalog, suggesting that no large‑scale automated exploitation has been reported yet. Nevertheless, the relatively high CVSS and the ease of exploitation warrant timely remediation.

Generated by OpenCVE AI on August 21, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iTop to version 3.2.3 or later to apply the vendor patch.
  • If an immediate upgrade is not possible, configure the system to disable or restrict the dashboard save feature for unauthenticated or low‑privilege users.
  • Continuously monitor web access logs for unexpected JavaScript payloads that may indicate an XSS attempt or successful exploitation.

Generated by OpenCVE AI on August 21, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Combodo
Combodo itop
Vendors & Products Combodo
Combodo itop

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.
Title Combodo iTop: Reflected XSS in dashboard save
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T20:37:20.408Z

Reserved: 2026-03-05T21:27:35.343Z

Link: CVE-2026-30865

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:16:56.970

Modified: 2026-08-21T21:16:56.970

Link: CVE-2026-30865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')