Executive brief
iTop is a web-based IT service management platform used to manage IT assets, incidents, and services. A reflected cross-site scripting vulnerability in the universal search feature allows authenticated users to craft malicious URLs that execute JavaScript in the browsers of other users who click them, potentially leading to account hijacking, session theft, or unauthorized actions within the platform.
Technical details
A reflected XSS vulnerability exists in the universal search page's handling of the oql_clause query parameter, where user input is reflected into the page without proper HTML sanitization. The vulnerability is in pages/UniversalSearch.php where the filter output was included directly in the HTML response without escaping. An attacker with low-privilege authentication can craft a malicious link containing JavaScript payload in the oql_clause parameter; when a victim visits the link, the script executes in their browser context with their privileges. The fix (version 3.2.3 and later) applies HTML escaping via utils::EscapeHtml() to the ToOQL() output.
Affected products
- Combodo iTop prior to 3.2.3
Timeline
- 2026-08-21: disclosed
- 2026-08-21: patched: Patched in versions 3.2.3 and 3.3.0