iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.
We have discovered 22 live websites that are affected by CVE-2025-24021.
Product | |
Category | Issue Trackers |
Vulnerable Domains | 22 live websites (129.41% of Combodo iTop install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 4 versions ( 80.00% of all versions) |
![]() | 4 websites |
![]() | 6 websites |
![]() | 2 websites |
![]() | 2 websites |
![]() | 1 websites |
![]() | 1 websites |
![]() | 1 websites |
![]() | 1 websites |
![]() | 1 websites |
.com | 7 websites |
.fr | 3 websites |
.ch | 2 websites |
.com.cn | 1 websites |
.cz | 1 websites |
.de | 1 websites |
.dk | 1 websites |
.net | 1 websites |
.org | 1 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.com | ![]() | **,***,*** | |
*********.com | ![]() | **,***,*** | |
*******.*****.fr | ![]() | **,***,*** | |
*******.**********.com | ![]() | **,***,*** | |
***.de | ![]() | **,***,*** | |
****.******.ch | ![]() | **,***,*** | |
*******.********.fr | ![]() | **,***,*** | |
****.*******.ro | ![]() | **,***,*** | |
*****.*********.cz | ![]() | **,***,*** | |
****.***.ch | ![]() | **,***,*** |
FAQ