Impact
Combodo iTop is a web‑based IT service management platform. In versions prior to 3.2.3 an authentication bypass flaw in exec.php allows a remote attacker who has no credentials to execute arbitrary PHP files located in the env-production directory. This flaw effectively grants the attacker full code‑execution privileges on the server, exposing the system to data exfiltration, tampering, and potential compromise of the underlying operating system.
Affected Systems
The vulnerability affects all Combodo iTop installations running versions older than 3.2.3. The flaw exists only when the env-production directory is present and accessible on a fresh iTop instance in a production environment.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. Because the attack vector requires unauthenticated access to a predictable web endpoint and the flaw is only present in default configurations, exploitation is straightforward once the target is reachable. No public exploit is currently known, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, so the exact exploitation probability is unknown, but the obvious access conditions imply a realistic risk for exposed deployments.
OpenCVE Enrichment