Junglewise Threat Intelligence

CVE-2026-30819: Combodo iTop reflected XSS in dashboard revert

CVE-2026-30819 · Severity: high · CVSS 7.3 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used by organizations to manage IT operations and service delivery. A reflected cross-site scripting (XSS) vulnerability in the dashboard revert functionality allows an attacker to inject malicious scripts that can steal user session data, modify displayed content, or redirect users to malicious sites when a user clicks a specially crafted link. The vulnerability requires user interaction and low-level privileges to exploit.

Technical details

A reflected XSS vulnerability exists in iTop versions prior to 3.2.3 in the /pages/ajax.render.php endpoint's dashboard revert functionality, where the dashboard_id parameter is not properly sanitized. The vulnerability is triggered via the revert_dashboard operation, which passes the unsanitized dashboard_id parameter without applying proper context-aware filtering. An attacker with low privileges can craft a malicious URL containing JavaScript payload in the dashboard_id parameter; when a victim user clicks the link, the payload executes in the victim's browser within the security context of the iTop application. The fix, released in version 3.2.3, applies proper sanitization using ENUM_SANITIZATION_FILTER_CONTEXT_PARAM to neutralize the payload.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-21: disclosed: CVE-2026-30819 published
  • 2026-08-10: patched: Fix released in versions 3.2.3 and 3.3.0

References

Related threats