CVE-2026-30864: Combodo iTop: Reflected XSS in dashboard revert
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access, a low-privileged account, and user interaction. The CVSS vector indicates exploitation has low complexity but requires a user to act on attacker-controlled content.
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. Version 3.2.3 contains the fix.
What is the potential impact of successful exploitation?
Successful reflected XSS can expose confidentiality and integrity beyond the vulnerable component's security scope, with a low availability impact. The supplied severity vector rates the issue 8.9 (high).