Junglewise Threat Intelligence

CVE-2026-30865: Combodo iTop reflected XSS in dashboard save

CVE-2026-30865 · Severity: high · CVSS 7.1 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used by organizations to manage IT assets and services. A reflected cross-site scripting (XSS) vulnerability in the dashboard save feature allows attackers to inject malicious scripts that execute in users' browsers, potentially compromising their sessions, stealing credentials, or performing unauthorized actions on behalf of logged-in administrators.

Technical details

The vulnerability is a reflected XSS flaw in the dashboard save functionality of iTop versions prior to 3.2.3. It allows an attacker to inject arbitrary JavaScript code through a malicious URL parameter, which executes in the victim's browser context when the dashboard is saved. The attack requires network access and user interaction (clicking a crafted link or visiting a compromised page), but does not require authentication or elevated privileges. An attacker can exploit this to steal session cookies, perform actions as the victim, or redirect users to phishing sites. The vulnerability has been patched in versions 3.2.3 and 3.3.0.

Affected products

  • Combodo iTop prior to 3.2.3

Timeline

  • 2026-08-10: disclosed
  • 2026-08-21: patched: Version 3.2.3 and 3.3.0 released

References

Related threats