CVE-2025-24022: iTop server vulnerable to portal code injection
Published May 14, 2025
·Updated
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.
Affected Software
4 affected components
Combodo iTop<2.7.12, <3.1.3, <3.2.1
Combodo iTop<2.7.12
Combodo iTop>=3.0.0<3.1.3
Combodo iTop>=3.2.0<3.2.1
Event History
May 14, 2025
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24022?
CVE-2025-24022 has a high severity due to its potential for server code execution.
2
How do I fix CVE-2025-24022?
To fix CVE-2025-24022, upgrade to iTop versions 2.7.12, 3.1.3, or 3.2.1.
3
What types of software are affected by CVE-2025-24022?
CVE-2025-24022 affects versions of the iTop IT Service Management tool prior to 2.7.12, 3.1.3, and 3.2.1.
4
Can I still use iTop if I have CVE-2025-24022?
Using iTop with CVE-2025-24022 poses a security risk, and it is strongly advised to upgrade immediately.
5
What does CVE-2025-24022 allow an attacker to do?
CVE-2025-24022 allows an attacker to execute server code through the frontend of iTop's portal.