---
id: CVE-2025-47932
title: Combodo iTop is a web based IT service management tool
summary: >-
  Combodo iTop is a web based IT service management tool. Versions prior to
  2.7.13 and 3.2.2 are vulnerable to cross-site scripting  when a dashboard is
  rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var
  responsible for …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: combodo
product: itop
affected:
  - itop < 2.7.13
  - 'itop >= 3.0.0, < 3.2.2'
patched:
  - itop 3.2.2
published: '2025-11-10'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-47932'
references:
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-rmxq-fx69-7wg5'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00222
epssPercentile: 0.11792
ingestedAt: '2026-10-07T21:54:15.007Z'
---

## Overview

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting  when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var responsible for the attack.

## Affected

- `itop < 2.7.13`
- `itop >= 3.0.0, < 3.2.2`

## Remediation

Upgrade past the affected range:

- `itop 3.2.2`
