CVE-2025-24022

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-05-14 15:15

Updated : 2025-08-01 18:39


NVD link : CVE-2025-24022

Mitre link : CVE-2025-24022

CVE.ORG link : CVE-2025-24022


JSON object : View

Products Affected

combodo

  • itop
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')