Remote Code Execution Vulnerability in iTop by Combodo
CVE-2025-24022

8.6HIGH

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
14 May 2025

What is CVE-2025-24022?

A vulnerability in the iTop web-based IT Service Management tool allows for remote code execution through its frontend portal prior to the release of versions 2.7.12, 3.1.3, and 3.2.1. This could potentially allow attackers to execute arbitrary server-side code, compromising the integrity and security of the affected system. Users are strongly advised to update to the latest versions to mitigate this risk.

Affected Version(s)

iTop < 2.7.12 < 2.7.12

iTop >= 3.0.0, < 3.1.3 < 3.0.0, 3.1.3

iTop >= 3.2.0, < 3.2.1 < 3.2.0, 3.2.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.