CVE-2023-48710: Combodo Itop
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be from a third-party module. The `pages/exec.php` script as been fixed to limit execution of PHP files only. Other file types won't be retrieved and exposed. The vulnerability is fixed in 2.7.10, 3.0.4, 3.1.1, and 3.2.0.
Affected products
- Combodo Itop: before 2.7.10 (fixed in 2.7.10); from 3.0.0, before 3.0.4 (fixed in 3.0.4); from 3.1.0, before 3.1.1 (fixed in 3.1.1)
Published 2024-04-15. Last modified 2026-06-17.