CVE-2025-48055: Combodo iTop has stored XSS in user portal's browse brick
Published Nov 10, 2025
·Updated
Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0.
Affected Software
2 affected components
Combodo iTop<3.2.2
Combodo iTop<3.2.2
Event History
Nov 10, 2025
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48055?
CVE-2025-48055 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2025-48055?
To fix CVE-2025-48055, upgrade Combodo iTop to version 3.2.2 or later.
3
What versions of Combodo iTop are affected by CVE-2025-48055?
Versions of Combodo iTop prior to 3.2.2 are affected by CVE-2025-48055.
4
What type of vulnerability is CVE-2025-48055?
CVE-2025-48055 is a cross-site scripting (XSS) vulnerability that can occur in the user portal.
5
Is CVE-2025-48055 fixed in the latest version of iTop?
Yes, CVE-2025-48055 is fixed in Combodo iTop versions 3.2.2 and 3.3.0.