CVE-2025-64167: Combodo iTop vulnerable to reflected XSS in webservices/export.php
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to JS execution) when editing the URL parameter. Versions 2.7.13 and 3.2.2 don't use export.php, which was deprecated. They use export-v2.php instead.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64167?
CVE-2025-64167 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-64167?
To fix CVE-2025-64167, you should upgrade to Combodo iTop version 2.7.13 or 3.2.2 or later.
What types of attacks are possible with CVE-2025-64167?
CVE-2025-64167 allows for cross-site scripting attacks that can lead to JavaScript execution in the user's browser.
Which versions of Combodo iTop are affected by CVE-2025-64167?
CVE-2025-64167 affects Combodo iTop versions prior to 2.7.13 and 3.2.2.
Is there a workaround for CVE-2025-64167 if I cannot upgrade?
There are no known effective workarounds for CVE-2025-64167, so upgrading is strongly recommended.