CVE-2024-56157: Combodo Itop
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scripting attack can be performed when importing this content. The issue is fixed in versions 3.1.3 and 3.2.1. As a workaround, check CSV content before importing it.
Affected products
- Combodo Itop: before 3.1.3 (fixed in 3.1.3); from 3.2.0, before 3.2.1 (fixed in 3.2.1)
Published 2025-05-14. Last modified 2026-06-17.