CVE-2025-24969: Combodo Itop

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

Affected products

  • Combodo Itop: before 3.2.1 (fixed in 3.2.1)

Published 2025-05-14. Last modified 2026-06-17.