Impact
This vulnerability allows unauthenticated users to retrieve uploaded sensitive files by using a URL that has been captured or sniffed from a legitimate session. The primary consequence is the unauthorized disclosure of potentially confidential data, which could compromise organizational secrets, personal information, or other sensitive content. The weakness originates from insufficient access control checks, mapped to CWE-200 (Information Exposure) and CWE-306 (Missing Authentication).
Affected Systems
Combodo iTop version 3.2.2 and earlier are affected. The issue was fixed in release 3.2.3, so any deployment below that version should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high severity flaw. While no EPSS score is available, the lack of authentication requirements means an attacker can exploit the flaw without credentials, simply by obtaining a valid URL. The vulnerability is not listed in the CISA KEV catalog at present, but the easy exploitation path raises the practical risk for exposed systems.
OpenCVE Enrichment