CVE-2026-31803: Combodo iTop: Reflected XSS in tag admin
Published Aug 21, 2026
·Updated
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in version 3.2.3.
Affected Software
1 affected component
Combodo iTop<3.2.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Aug 21, 2026
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Combodo iTop versions prior to 3.2.3 are affected. The issue is in the tag administration page, pages/tagadmin.php.
2
What must an attacker do to exploit this issue?
The attacker needs a low-privileged account and must induce a user to interact with a crafted request or content. The vulnerability is remotely reachable and has low attack complexity.
3
What is the remediation?
Update Combodo iTop to version 3.2.3, which fixes the reflected XSS issue.