CVE-2026-30865: Combodo iTop: Reflected XSS in dashboard save
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. The issue is fixed in version 3.2.3.
What does exploitation require?
The CVSS vector indicates that exploitation can be performed over the network with low attack complexity and no attacker privileges, but it requires user interaction.
What is the impact of successful exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at a low level, with scope changed according to the supplied CVSS vector.