CVE-2025-47773: Combodo iTop has XSS vulnerability in /pages/ajax.render.php
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Versions 2.7.13 and 3.2.2 protect rendered HTML content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47773?
CVE-2025-47773 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-47773?
To fix CVE-2025-47773, you need to upgrade Combodo iTop to version 2.7.13 or 3.2.2 or later.
What types of attacks are possible with CVE-2025-47773?
CVE-2025-47773 allows attackers to perform cross-site scripting attacks, potentially leading to data theft or execution of malicious scripts.
Which versions of Combodo iTop are affected by CVE-2025-47773?
Combodo iTop versions prior to 2.7.13 and 3.2.2 are affected by CVE-2025-47773.
Is there a patch available for CVE-2025-47773?
Yes, a patch is available by upgrading to Combodo iTop version 2.7.13 or 3.2.2, which protects against the vulnerability.