CVE-2025-24969: Combodo Itop
Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.
iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.
Affected products
- Combodo Itop: before 3.2.1 (fixed in 3.2.1)
Published 2025-05-14. Last modified 2026-06-17.