Remote Code Execution Vulnerability in iTop by Combodo
CVE-2025-24022
8.6HIGH
What is CVE-2025-24022?
A vulnerability in the iTop web-based IT Service Management tool allows for remote code execution through its frontend portal prior to the release of versions 2.7.12, 3.1.3, and 3.2.1. This could potentially allow attackers to execute arbitrary server-side code, compromising the integrity and security of the affected system. Users are strongly advised to update to the latest versions to mitigate this risk.
Affected Version(s)
iTop < 2.7.12 < 2.7.12
iTop >= 3.0.0, < 3.1.3 < 3.0.0, 3.1.3
iTop >= 3.2.0, < 3.2.1 < 3.2.0, 3.2.1