CVE-2025-49145

iTop admin can drop iTop database using webhooks

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.


We have discovered 24 live websites that are affected by CVE-2025-49145.

Run a Free Instant Scan




Affected Software

Product  Combodo iTop
Category Issue Trackers
Vulnerable Domains24 live websites (100% of Combodo iTop install base)
Vulnerable Versions
  • from 0 through 2.7.13
  • from 3 through 3.2.2
Vulnerable Versions Count4 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Nov 10, 2025
  • Updated - Nov 10, 2025

Website Distribution by Country

Number of websites using CVE-2025-49145
United States2 websites



France6 websites
Germany4 websites
Netherlands4 websites
Switzerland2 websites
Denmark1 websites
GB1 websites
Israel1 websites
Romania1 websites

Website Distribution by TLD

Number of websites using CVE-2025-49145
.com7 websites
.fr3 websites
.nl3 websites
.ch2 websites
.de2 websites
.net2 websites
.com.cn1 websites
.dk1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-49145

Top websites that are affected by CVE-2025-49145. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States**,***,***
*********.com Germany**,***,***
*******.*****.fr France**,***,***
*******.**********.com Singapore**,***,***
***.de Germany**,***,***
*******.*******.fr France**,***,***
****.******.ch Switzerland**,***,***
***.****.*********.com Germany**,***,***
****.*******.ro Romania**,***,***
****.***.ch France**,***,***
See full domain list

FAQ

CVE-2025-49145 is Incorrect Authorization in Combodo iTop
A total of 24 websites have been identified as vulnerable to CVE-2025-49145, based on global website indexing conducted by WebTechSurvey.
The Combodo iTop is affected by the CVE-2025-49145 vulnerability.
Combodo iTop versions up to 3.2.2 are vulnerable to CVE-2025-49145.
CVE-2025-49145 is resolved in version 3.2.2 of Combodo iTop.