CVE-2025-24969: iTop portal user can see any other contact's picture
Published May 14, 2025
·Updated
iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.
Affected Software
2 affected components
Combodo iTop<3.2.1
Combodo iTop<3.2.1
Event History
May 14, 2025
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24969?
CVE-2025-24969 is classified as a medium severity vulnerability affecting iTop versions prior to 3.2.1.
2
How do I fix CVE-2025-24969?
To fix CVE-2025-24969, upgrade iTop to version 3.2.1 or later.
3
What is the impact of CVE-2025-24969?
The impact of CVE-2025-24969 allows unauthorized users to view other contacts' pictures by modifying the picture ID in the URL.
4
Which versions of iTop are affected by CVE-2025-24969?
iTop versions prior to 3.2.1 are affected by CVE-2025-24969.
5
Is there any workaround for CVE-2025-24969?
There is no known workaround for CVE-2025-24969, and upgrading to the patched version is recommended.