CVE-2025-48878: Combodo iTop vulnerable to IDOR with ModuleInstallation object
Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version 3.2.2 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48878?
The severity of CVE-2025-48878 is considered medium due to the potential for unauthorized access to module installations.
How do I fix CVE-2025-48878?
To fix CVE-2025-48878, upgrade Combodo iTop to version 3.2.2 or later.
What versions of Combodo iTop are affected by CVE-2025-48878?
CVE-2025-48878 affects all versions of Combodo iTop in the 3.x branch prior to 3.2.2.
What kind of vulnerability is CVE-2025-48878?
CVE-2025-48878 is classified as an insecure direct object reference vulnerability.
Who is impacted by CVE-2025-48878?
Users with the Service desk agent profile in older versions of Combodo iTop are impacted by CVE-2025-48878.