Executive brief
iTop is a web-based IT service management platform used for tracking and managing IT assets, incidents, and configurations. The vulnerability allows unauthenticated attackers to access sensitive uploaded images by guessing or sniffing document URLs, potentially exposing confidential organizational information without requiring login credentials.
Technical details
The vulnerability is an insecure direct object reference (IDOR) / missing authentication issue in the image serving endpoint (ajax.document.php). Unauthenticated users can access uploaded images by crafting or intercepting direct URLs to documents, bypassing the intended authentication requirement. The attack requires network access and no user interaction; an attacker only needs to discover or sniff valid document URLs. The fix involved forcing authentication on the inline image endpoints by adding LoginWebPage::DoLoginEx() enforcement. Versions 3.2.3 and 3.3.0 and later are patched.
Affected products
- Combodo iTop prior to 3.2.3
Timeline
- 2026-08-21: disclosed
- 2026-08-21: patched: Fixed in version 3.2.3 and 3.3.0