Impact
Combodo iTop is a web based IT service management tool that includes a universal search feature. A Reflected Cross‑Site Scripting (XSS) flaw allows an attacker to embed malicious script that is executed in the victim’s browser when the search string is returned. The vulnerability can be used to steal authentication cookies, hijack sessions, deface content, or execute further malicious code on the client side.
Affected Systems
The flaw affects all Versons of Combodo iTop prior to version 3.2.3. The CNA notes that iTop 3.2.3 and later contain a fix. It applies to the Combodo iTop product as a whole; no specific patch versions other than 3.2.3 are mentioned as fixed.
Risk and Exploitability
The CVSS score of 8 indicates a high severity level. Because the flaw is reflected, an attacker must deliver a crafted URL to the victim, and the victim must click it or for the navigation to include the malicious search string. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying that it is not actively exploited at the time of this report, but the high security rating and the potential for phishing or click‑jacking attacks warrant immediate attention.
OpenCVE Enrichment