CVE-2025-47286High· 7.2▾ TwilightCombodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and chec…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.
itop < 2.7.13itop >= 3.0.0, < 3.2.2Upgrade past the affected range:
itop 3.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-48065High· 8.8Combodo iTop is a web based IT service management tool
CVE-2025-48878Medium· 4.3Combodo iTop is a web based IT service management tool
CVE-2025-49145High· 8.7Combodo iTop is a web based IT service management tool
CVE-2025-47932High· 8.8Combodo iTop is a web based IT service management tool
CVE-2025-48055High· 8.5Combodo iTop is a web based IT service management tool
CVE-2025-47773High· 8.8Combodo iTop is a web based IT service management tool