CVE-2025-24021

iTop doesn't have mass assignment of fields in the portal form

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.


We have discovered 22 live websites that are affected by CVE-2025-24021.

Run a Free Instant Scan




Affected Software

Product  Combodo iTop
Category Issue Trackers
Vulnerable Domains22 live websites (129.41% of Combodo iTop install base)
Vulnerable Versions
  • from 0 before 2.7.12
  • from 3 before 3.1.3
  • from 3.2 before 3.2.1
Vulnerable Versions Count4 versions ( 80.00% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - May 14, 2025
  • Updated - May 14, 2025

CVE-2025-24021 usage by Country

United States4 websites



France6 websites
Switzerland2 websites
Germany2 websites
Czech Republic1 websites
Denmark1 websites
GB1 websites
Israel1 websites
Romania1 websites

CVE-2025-24021 usage by TLD

.com7 websites
.fr3 websites
.ch2 websites
.com.cn1 websites
.cz1 websites
.de1 websites
.dk1 websites
.net1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-24021

Top websites that are affected by CVE-2025-24021. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States**,***,***
*********.com Germany**,***,***
*******.*****.fr France**,***,***
*******.**********.com Singapore**,***,***
***.de Germany**,***,***
****.******.ch Switzerland**,***,***
*******.********.fr France**,***,***
****.*******.ro Romania**,***,***
*****.*********.cz Czech Republic**,***,***
****.***.ch France**,***,***
See full domain list

FAQ

CVE-2025-24021 is Missing Authorization in Combodo iTop
A total of 22 websites have been identified as vulnerable to CVE-2025-24021, based on global website indexing conducted by WebTechSurvey.
The Combodo iTop is affected by the CVE-2025-24021 vulnerability.
Combodo iTop versions up to 3.2.1 are vulnerable to CVE-2025-24021.
CVE-2025-24021 is resolved in version 3.2.1 of Combodo iTop.