Impact
Combodo iTop is a web‑based IT service management tool. A reflected Cross‑Site Scripting vulnerability was identified in pages/tagadmin.php. The flaw allows an attacker to inject arbitrary client‑side script into the page by manipulating the request parameters, which is then executed in the victim’s browser. While the flaw does not provide direct code execution on the server, it can be used to steal session cookies, deface the interface, or redirect users to malicious sites, compromising confidentiality and integrity from the victim’s perspective.
Affected Systems
Combodo iTop versions prior to 3.2.3 are affected. This includes any installation running iTop before the release of 3.2.3. The vulnerability resides in the tagadmin.php component of the application.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity. EPSS information is not available, so the probability of exploitation cannot be quantified. The vulnerability is listed as not in the CISA KEV catalog. The likely attack vector is a reflected XSS that requires the victim to visit a crafted URL; the attacker must have an opportunity to deliver or embed the malicious link. Exploitation does not require privileged access or authentication, making it accessible to attackers that can target the web application or influence users to click the link.
OpenCVE Enrichment