Impact
Prior to version 3.2.3, Combodo iTop’s ajax.render.php returned error messages that included sensitive internal information. The disclosed data can expose configuration details and other confidential information to unauthorized users, creating a risk of data leakage. The vulnerability is classified as CWE-209: Information Exposure Through an Error Message and carries a CVSS score of 3.5, indicating a low severity impact on confidentiality.
Affected Systems
The flaw affects the Combodo iTop IT service management tool for all releases prior to 3.2.3. Any deployment running iTop 3.2.2 or older is vulnerable, regardless of platform or operating system.
Risk and Exploitability
The CVSS score of 3.5 results in a low overall severity, and the EPSS score is not available, suggesting limited evidence of exploitation. Because the flaw is revealed through error handling on the web interface, the likely attack vector is unauthenticated or low-privilege access that triggers an error condition. The vulnerability is not listed in the CISA KEV catalog, reinforcing the low risk assessment for large‑scale exploitation.
OpenCVE Enrichment