Reflected XSS Vulnerability in Combodo iTop IT Service Management Tool
CVE-2026-30890
8HIGH
What is CVE-2026-30890?
Combodo iTop, a web-based IT service management solution, is affected by a reflected Cross-Site Scripting (XSS) vulnerability present in the synchro import script prior to version 3.2.3. This security flaw could allow attackers to inject malicious scripts, compromising the security of users interacting with the impacted application. The issue has been addressed in version 3.2.3, where adequate security measures have been implemented to mitigate this risk effectively.
Affected Version(s)
iTop < 3.2.3
