Description
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
Published: 2026-08-21
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A reflected Cross‑Site Scripting (XSS) flaw exists in the foreign key search criteria API of Combodo iTop. The vulnerability can cause malicious scripts to run in a victim’s browser when the API is invoked with crafted input. Successful exploitation can enable an attacker to steal session cookies, hijack user accounts, or modify page content, representing a client‑side code execution risk defined by CWE‑79.

Affected Systems

Combodo’s iTop service‑management platform versions prior to 3.2.3 are vulnerable. The issue originates in the web‑based search functionality exposed by these releases.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as High severity. While the EPSS score is not available, the absence of a KEV listing suggests no known active exploitation, though the lack of data does not eliminate risk. The attack vector is likely remote, soliciting a crafted request to the foreign key search endpoint, and requires user interaction with the resulting page. Even if authentication is needed, the vulnerability remains dangerous because it can be used to compromise any user who views the reflected payload.

Generated by OpenCVE AI on August 21, 2026 at 22:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iTop to version 3.2.3 or later, which includes the security fix
  • If upgrading is not immediately possible, restrict or block access to the foreign key search API for untrusted users
  • Implement strong Content‑Security‑Policy headers and ensure all user‑supplied data is properly escaped or validated to mitigate XSS

Generated by OpenCVE AI on August 21, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
Title Combodo iTop: Reflected XSS in foreign key search criteria
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T21:25:03.819Z

Reserved: 2026-03-18T02:42:27.508Z

Link: CVE-2026-33240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T22:16:36.863

Modified: 2026-08-21T22:16:36.863

Link: CVE-2026-33240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')