CVE-2020-12779: Combodo Itop

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

Affected products

  • Combodo Itop: before 2.7.0 (fixed in 2.7.0); version 2.7.0 only

Published 2020-08-10. Last modified 2026-06-17.