Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.
Published: 2026-08-21
Score: 8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Combodo iTop is a web based IT service management tool that includes a universal search feature. A Reflected Cross‑Site Scripting (XSS) flaw allows an attacker to embed malicious script that is executed in the victim’s browser when the search string is returned. The vulnerability can be used to steal authentication cookies, hijack sessions, deface content, or execute further malicious code on the client side.

Affected Systems

The flaw affects all Versons of Combodo iTop prior to version 3.2.3. The CNA notes that iTop 3.2.3 and later contain a fix. It applies to the Combodo iTop product as a whole; no specific patch versions other than 3.2.3 are mentioned as fixed.

Risk and Exploitability

The CVSS score of 8 indicates a high severity level. Because the flaw is reflected, an attacker must deliver a crafted URL to the victim, and the victim must click it or for the navigation to include the malicious search string. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying that it is not actively exploited at the time of this report, but the high security rating and the potential for phishing or click‑jacking attacks warrant immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Combodo iTop to version 3.2.3 or later to remove the reflected XSS vector.
  • If an upgrade cannot be performed immediately, disable or restrict the universal search feature or enforce input sanitization on the search query parameter.
  • Implement a web application firewall rule to block any search requests containing script tags or other suspicious characters.

Generated by OpenCVE AI on August 21, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Combodo
Combodo itop
Vendors & Products Combodo
Combodo itop

Fri, 21 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2.3.
Title Combodo iTop: Reflected XSS in universal search
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T21:42:30.174Z

Reserved: 2026-03-09T21:59:02.686Z

Link: CVE-2026-31880

cve-icon Vulnrichment

Updated: 2026-08-21T21:20:32.304Z

cve-icon NVD

Status : Received

Published: 2026-08-21T21:16:57.403

Modified: 2026-08-21T22:16:36.430

Link: CVE-2026-31880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')