Executive brief
Combodo iTop is a web-based tool used by IT teams to manage IT services and incidents. A reflected cross-site scripting (XSS) vulnerability in the dashboard revert feature allows attackers to inject malicious scripts that steal session cookies and sensitive data from authenticated users who click a crafted link, potentially compromising accounts and exposing confidential IT service information.
Technical details
A reflected XSS vulnerability exists in the dashboard revert functionality of iTop prior to version 3.2.3. The vulnerability is triggered when an attacker crafts a malicious URL and tricks an authenticated user with low or higher privileges into clicking it. The attack requires user interaction (clicking the link) and results in arbitrary JavaScript execution in the victim's browser session with scope change, allowing access to session tokens and sensitive data visible to the user. The vulnerability has been patched in versions 3.2.3 and 3.3.0.
Affected products
- Combodo iTop prior to 3.2.3
Timeline
- 2026-08-10: disclosed
- 2026-08-24: advisory: CVE-2026-30864 published
- 2026-08-24: patched: Fixed in versions 3.2.3 and 3.3.0