PT-2025-46195 · Comodo · Itop

Published

2025-11-10

·

Updated

2025-11-21

·

CVE-2025-48878

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Combodo iTop versions prior to 3.2.2
Description Combodo iTop is a web based IT service management tool. An insecure direct object reference allows a user, such as one with a Service desk agent profile, to create a ModuleInstallation object when they should not be able to. This occurs in versions on the 3.x branch prior to version 3.2.2.
Recommendations Update to version 3.2.2 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-48878
GHSA-RJ75-7CGW-4556

Affected Products

Itop