CVE-2025-24785: Combodo Itop
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided layout_class before saving the dashboard.
Affected products
- Combodo Itop: from 3.2.0, before 3.2.1 (fixed in 3.2.1)
Published 2025-05-14. Last modified 2026-06-17.