PT-2025-46193 · Comodo · Itop

Published

2025-11-10

·

Updated

2025-11-10

·

CVE-2025-48055

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 3.2.2
Description Combodo iTop is a web-based IT service management tool. A cross-site scripting issue can occur when displaying content in a browse brick within the user portal. This allows for the execution of malicious scripts in a user's browser when accessing certain areas of the portal.
Recommendations Upgrade to version 3.2.2. Upgrade to version 3.3.0.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-48055
GHSA-684H-F39J-5GQ8

Affected Products

Itop