Impact
Improper access control in Combodo iTop’s ajax.render.php and ajax.document.php allows an attacker to retrieve documents without any permission checks. The flaw is a classic missing authorization failure, identified as CWE-862. If an attacker supplies a valid URL for these scripts, confidential documents can be read, potentially exposing sensitive internal information and violating confidentiality.
Affected Systems
The vulnerability affects Combodo iTop versions prior to 3.2.3. All installations running a version earlier than 3.2.3 are susceptible; upgrades to 3.2.3 or later remove the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, and the flaw is not listed in CISA KEV. Attackers can exploit the weakness remotely by issuing HTTP requests to the vulnerable scripts from any network location that can reach the server. Because the flaw lacks advanced prerequisites, the risk of exploitation exists but may be limited by network segmentation and web‑application controls.
OpenCVE Enrichment