Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Defencetechsecurity

#19205of 53,608
13.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-7911
6.8
2025-02-25
Comodo · Itop · CVE-2025-27139
**Name of the Vulnerable Software and Affected Versions** Combodo iTop versions prior to 2.7.12 Combodo iTop versions prior to 3.1.2 Combodo iTop versions prior to 3.2.0 **Description** The issue is related to cross-site scripting that occurs when the preferences page is opened. **Recommendations** For versions prior to 2.7.12, update to version 2.7.12 or later. For versions prior to 3.1.2, update to version 3.1.2 or later. For versions prior to 3.2.0, update to version 3.2.0 or later.
PT-2024-35084
7.1
2024-11-07
Comodo · Combodo Itop · CVE-2024-51995
**Name of the Vulnerable Software and Affected Versions** Combodo iTop versions prior to 3.2.0 **Description** Combodo iTop is a web-based IT Service Management tool. An issue allows an attacker to request any `route` as long as they specify an `operation` that is allowed. The estimated number of potentially affected devices worldwide is not available. There are no known real-world incidents where this issue was exploited. **Recommendations** For versions prior to 3.2.0, upgrade to version 3.2.0 to address the issue. As a temporary workaround, consider restricting access to the `ajax.render.php` page to minimize the risk of exploitation. Avoid using arbitrary `routes` in the affected API endpoints until the issue is resolved.