CVE-2025-24021: Combodo Itop

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.

Affected products

  • Combodo Itop: before 2.7.12 (fixed in 2.7.12); from 3.0.0, before 3.1.3 (fixed in 3.1.3); from 3.2.0, before 3.2.1 (fixed in 3.2.1)

Published 2025-05-14. Last modified 2026-06-17.