CVE-2026-30890: Combodo iTop: Reflected XSS in synchro/synchro_import.php
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. The issue is in the synchro/synchro_import.php script.
What access does an attacker need?
The supplied severity vector indicates network-reachable exploitation with low privileges and required user interaction. This means an attacker must have a low-privileged account and induce a user to interact with crafted content.
What is the remediation?
Upgrade Combodo iTop to version 3.2.3, which fixes the reflected XSS vulnerability.