Executive brief
Combodo iTop is a web-based IT service management platform used by organizations to track and manage IT assets and incidents. Prior to version 3.2.3, the application exposed sensitive information through detailed error messages displayed to users. An attacker with low-level access could trigger errors and read potentially sensitive system details that should not be disclosed.
Technical details
This is an information disclosure vulnerability in the ajax.render.php file of iTop. The vulnerable code directly echoed exception error messages to the user interface without filtering for sensitive content, allowing detailed exception details and stack traces to leak to users with low-level privileges who trigger errors. The attack vector is network-based and requires low-level user privileges and user interaction (triggering an error condition). The fix (committed in version 3.2.3) replaces the direct exception message output with a generic error message while logging the actual error details server-side. No known public exploits exist, and patches are available in versions 3.2.3 and 3.3.0.
Affected products
- Combodo iTop before 3.2.3
Timeline
- 2026-08-10: disclosed
- 2026-08-21: patched: Fixed in versions 3.2.3 and 3.3.0