CVE-2025-24785: Combodo Itop

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided layout_class before saving the dashboard.

Affected products

  • Combodo Itop: from 3.2.0, before 3.2.1 (fixed in 3.2.1)

Published 2025-05-14. Last modified 2026-06-17.