Executive brief
Combodo iTop is a web-based IT service management platform used by organizations to manage IT assets and services. A reflected cross-site scripting (XSS) vulnerability in the dashboard save feature allows attackers to inject malicious scripts that execute in users' browsers, potentially compromising their sessions, stealing credentials, or performing unauthorized actions on behalf of logged-in administrators.
Technical details
The vulnerability is a reflected XSS flaw in the dashboard save functionality of iTop versions prior to 3.2.3. It allows an attacker to inject arbitrary JavaScript code through a malicious URL parameter, which executes in the victim's browser context when the dashboard is saved. The attack requires network access and user interaction (clicking a crafted link or visiting a compromised page), but does not require authentication or elevated privileges. An attacker can exploit this to steal session cookies, perform actions as the victim, or redirect users to phishing sites. The vulnerability has been patched in versions 3.2.3 and 3.3.0.
Affected products
- Combodo iTop prior to 3.2.3
Timeline
- 2026-08-10: disclosed
- 2026-08-21: patched: Version 3.2.3 and 3.3.0 released