Junglewise Threat Intelligence

CVE-2026-31803: Combodo iTop reflected XSS in tag admin

CVE-2026-31803 · Severity: high · CVSS 8 · Published 2026-08-21

Technologies: Combodo iTop. Vendors: Combodo.

Executive brief

Combodo iTop is a web-based IT service management platform used by organizations to manage IT operations, change requests, and service incidents. A reflected cross-site scripting (XSS) vulnerability in the tag administration interface allows an authenticated attacker to inject malicious scripts that execute in a victim's browser, potentially leading to session hijacking, credential theft, or unauthorized modification of IT service data.

Technical details

A reflected XSS vulnerability exists in pages/tagadmin.php prior to version 3.2.3, where user-controlled filter parameters are rendered into HTML comments without proper escaping. The vulnerability requires an authenticated user with low privileges to be tricked into clicking a malicious link. An attacker can craft a URL containing JavaScript payloads that execute in the context of the victim's session, allowing theft of session tokens, CSRF attacks, or lateral movement within the IT service management system. The fix (commit ab8e7bd) adds HTML escaping via utils::EscapeHtml() to sanitize the filter output.

Affected products

  • Combodo iTop 3.2.2 and earlier

Timeline

  • 2026-08-10: disclosed
  • 2026-08-21: patched: Fixed in versions 3.2.3 and 3.3.0

References

Related threats