CVE-2019-13966: Combodo Itop
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).
Affected products
- Combodo Itop: up to and including 2.6.0
Published 2020-02-14. Last modified 2026-06-17.