CVE-2025-24021: iTop doesn't have mass assignment of fields in the portal form
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24021?
CVE-2025-24021 is considered a moderate severity vulnerability due to its potential for unauthorized data manipulation.
How do I fix CVE-2025-24021?
To fix CVE-2025-24021, upgrade to versions 2.7.12, 3.1.3, or 3.2.1 of iTop.
Who is affected by CVE-2025-24021?
CVE-2025-24021 affects users of iTop prior to versions 2.7.12, 3.1.3, and 3.2.1.
What impact does CVE-2025-24021 have?
CVE-2025-24021 allows users with portal access to incorrectly set values to object fields, leading to potential data integrity issues.
Is there a workaround for CVE-2025-24021?
There is no known workaround for CVE-2025-24021; updating to a patched version is recommended.