Impact
Combodo iTop, a web-based IT service management platform, has a flaw that allows unauthenticated users to delete the .readonly file created during setup. Removing this file removes a write protection mechanism, resulting in arbitrary code execution on the server. The vulnerability is a classic example of an injection-based code execution issue, identified as CWE-94, and can compromise the confidentiality, integrity, and availability of the system.
Affected Systems
The flaw affects all Combodo iTop installations running a version earlier than 3.2.3. Users deploying the affected releases must verify that their instance is running a vulnerable version and apply the necessary update.
Risk and Exploitability
With a CVSS score of 9.4, the vulnerability is considered critical. The EPSS score is not disclosed, but the lack of a KEV listing does not diminish the potential for exploitation, as the attack requires only unauthenticated web traffic to delete a file. The likely attack vector is through a client‑initiated HTTP request targeting the file system. Because the flaw permits code execution, a remote attacker could gain administrative control or exfiltrate data, making this a high‑impact security issue.
OpenCVE Enrichment