Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Combodo
Combodo itop |
|
| Vendors & Products |
Combodo
Combodo itop |
Mon, 10 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it. | |
| Title | Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-10T18:38:40.283Z
Updated: 2025-11-10T19:47:01.682Z
Reserved: 2025-05-05T16:53:10.374Z
Link: CVE-2025-47286
Updated: 2025-11-10T19:25:29.311Z
Status : Awaiting Analysis
Published: 2025-11-10T19:15:57.043
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-47286
No data.