CVE-2025-47932: Combodo iTop vulnerable to reflected XSS in ajax.render.php render_dashboard
Published Nov 10, 2025
·Updated
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var responsible for the attack.
Affected Software
3 affected components
Combodo iTop<2.7.13, <3.2.2
Combodo iTop<2.7.13
Combodo iTop>=3.0.0<3.2.2
Event History
Nov 10, 2025
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47932?
CVE-2025-47932 has a medium severity rating due to its potential for cross-site scripting vulnerabilities.
2
How do I fix CVE-2025-47932?
To fix CVE-2025-47932, upgrade to Combodo iTop version 2.7.13 or 3.2.2 or later.
3
What versions of Combodo iTop are affected by CVE-2025-47932?
Combodo iTop versions prior to 2.7.13 and 3.2.2 are affected by CVE-2025-47932.
4
What type of vulnerability is CVE-2025-47932?
CVE-2025-47932 is a cross-site scripting (XSS) vulnerability related to AJAX calls in dashboards.
5
What is the impact of exploiting CVE-2025-47932?
Exploiting CVE-2025-47932 could allow attackers to execute arbitrary scripts in the context of the user’s session.