PT-2025-21173 · Itop · Itop
CVE-2025-24785
·
Publicado
2025-05-14
·
Atualizado
2025-05-14
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
iTop version 3.2.0
Description:
The issue allows an attacker to send a URL to the server, triggering a PHP error. This error causes the start page to crash for the next user attempting to load the dashboard.
Recommendations:
For version 3.2.0, update to version 3.2.1, which fixes the issue by checking the provided
layout class before saving the dashboard.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Itop