PT-2025-46194 · Comodo · Itop

Published

2025-11-10

·

Updated

2025-11-10

·

CVE-2025-48065

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 2.7.13 Combodo iTop versions prior to 3.2.2
Description Combodo iTop, a web-based IT service management tool, is susceptible to cross-site scripting. This occurs when a field displaying an error contains malicious content.
Recommendations Update to Combodo iTop version 2.7.13 or later. Update to Combodo iTop version 3.2.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-48065
GHSA-292C-HGCF-2G22

Affected Products

Itop