Impact
Combodo iTop is a web-based IT service management tool that is vulnerable before version 3.2.3 to PHP object injection through the user preference feature. The flaw allows an attacker to construct malicious serialized objects that are instantiated when the preference data is processed, enabling execution of arbitrary PHP code on the server. This gives the attacker full control over the application environment, compromising confidentiality, integrity, and availability.
Affected Systems
All installations of Combodo iTop earlier than 3.2.3, regardless of operating system or web server, are affected. Any system that has not applied the 3.2.3 update remains vulnerable.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity, while the EPSS score is not available so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker can exploit the flaw by sending specially crafted user preference data—likely via an HTTP POST request to the preferences endpoint—without needing special privileges. Attacks could therefore be conducted from unauthenticated or authenticated accounts depending on the access controls of the target installation.
OpenCVE Enrichment