CVE-2026-33240: Combodo iTop: Reflected XSS in foreign key search criteria
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Combodo iTopto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
Which deployments are affected?
Combodo iTop versions before 3.2.3 are affected. Version 3.2.3 includes the fix.
What must an attacker do to exploit this issue?
The attack is network-reachable and requires no privileges, but it requires user interaction. Exploitation involves reflected script injection through the foreign key search criteria API.
What is the impact if exploitation succeeds?
The reported severity vector indicates high impacts to confidentiality, integrity, and availability in the context of the affected application.