Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
Published: 2026-08-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

A reflected Cross‑Site Scripting (XSS) flaw exists in the foreign key search criteria API of Combodo iTop. The vulnerability can cause malicious scripts to run in a victim’s browser when the API is invoked with crafted input. Successful exploitation can enable an attacker to steal session cookies, hijack user accounts, or modify page content, representing a client‑side code execution risk defined by CWE‑79.

Affected Systems

Combodo’s iTop service‑management platform versions prior to 3.2.3 are vulnerable. The issue originates in the web‑based search functionality exposed by these releases.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as High severity. While the EPSS score is not available, the absence of a KEV listing suggests no known active exploitation, though the lack of data does not eliminate risk. The attack vector is likely remote, soliciting a crafted request to the foreign key search endpoint, and requires user interaction with the resulting page. Even if authentication is needed, the vulnerability remains dangerous because it can be used to compromise any user who views the reflected payload.

Generated by OpenCVE AI on August 21, 2026 at 22:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iTop to version 3.2.3 or later, which includes the security fix
  • If upgrading is not immediately possible, restrict or block access to the foreign key search API for untrusted users
  • Implement strong Content‑Security‑Policy headers and ensure all user‑supplied data is properly escaped or validated to mitigate XSS

Generated by OpenCVE AI on August 21, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Combodo
Combodo itop
Vendors & Products Combodo
Combodo itop

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
Title Combodo iTop: Reflected XSS in foreign key search criteria
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-25T13:30:28.076Z

Reserved: 2026-03-18T02:42:27.508Z

Link: CVE-2026-33240

cve-icon Vulnrichment

Updated: 2026-08-25T13:30:09.233Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T22:16:36.863

Modified: 2026-09-09T21:06:39.057

Link: CVE-2026-33240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')