CVE-2018-10642: Combodo Itop

High severity, CVSS 7.2. EPSS: 7.4% chance of exploitation in the next 30 days.

Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().

Affected products

  • Combodo Itop: up to and including 2.4.1

Published 2018-05-02. Last modified 2026-06-17.