PT-2026-79489 · Comodo · Itop
CVE-2026-33240
·
Published
2026-08-21
·
Updated
2026-08-25
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Combodo iTop versions prior to 3.2.3
Description
Combodo iTop is a web-based IT service management tool. A reflected cross-site scripting (XSS) flaw exists in the foreign key search criteria API, where user-supplied input is not properly sanitized before being returned in the HTTP response. This allows an attacker to inject arbitrary client-side scripts that execute in the victim's browser, potentially leading to session hijacking, data exfiltration, or website defacement. The attack typically requires network connectivity to the application and social engineering to trick an authenticated user into clicking a malicious link.
Recommendations
Upgrade to version 3.2.3 or later.
Restrict access to the foreign key search criteria API to minimize the risk of exploitation until the upgrade is complete.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itop