CVE-2025-48065: Combodo iTop vulnerable to reflected XSS via objection edition form error
Published Nov 10, 2025
·Updated
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered HTML content.
Affected Software
3 affected components
Combodo iTop<2.7.13, <3.2.2
Combodo iTop<2.7.13
Combodo iTop>=3.0.0<3.2.2
Event History
Nov 10, 2025
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48065?
CVE-2025-48065 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2025-48065?
To fix CVE-2025-48065, update to Combodo iTop version 2.7.13 or 3.2.2 or later.
3
What types of attacks are possible due to CVE-2025-48065?
CVE-2025-48065 allows attackers to execute malicious scripts in the context of the affected web application.
4
Who is affected by CVE-2025-48065?
Users of Combodo iTop versions prior to 2.7.13 and 3.2.2 are affected by CVE-2025-48065.
5
What functionality is impacted by CVE-2025-48065?
CVE-2025-48065 impacts the rendering of HTML content in error fields, which may contain malicious content.