---
id: CVE-2025-48065
title: Combodo iTop is a web based IT service management tool
summary: >-
  Combodo iTop is a web based IT service management tool. Versions prior to
  2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an
  error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered
  HTML cont…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: combodo
product: itop
affected:
  - itop < 2.7.13
  - 'itop >= 3.0.0, < 3.2.2'
patched:
  - itop 3.2.2
published: '2025-11-10'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48065'
references:
  - url: 'https://github.com/Combodo/iTop/security/advisories/GHSA-292c-hgcf-2g22'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00222
epssPercentile: 0.11792
ingestedAt: '2026-10-07T21:54:15.008Z'
---

## Overview

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with an error contains malicious content. Versions 2.7.13 and 3.2.2 protect rendered HTML content.

## Affected

- `itop < 2.7.13`
- `itop >= 3.0.0, < 3.2.2`

## Remediation

Upgrade past the affected range:

- `itop 3.2.2`
