Sceawere

Vulnerability Detail

CVE-2026-30826UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Combodo iTop Reflected XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
3h ago
Vendor
Combodo
Product
iTop
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-08-21T21:16:56.830Z",
  "pubdate": "2026-08-21T21:16:56.830Z",
  "executiveSummary": "A Reflected Cross-Site Scripting (XSS) vulnerability exists within the testing OQL query functionality of Combodo iTop prior to version 3.2.3. This security flaw allows remote attackers to inject malicious client-side scripts, typically JavaScript, into HTTP requests targeting the vulnerable application endpoints. When processed and reflected back to the victim in the HTTP response, the script executes within the context of the victim's browser session. The primary impact of this vulnerability includes session hijacking, unauthorized access to sensitive application data, credential theft, and the manipulation or unauthorized execution of administrative or user actions within the affected iTop instance. The vulnerability affects all Combodo iTop deployments running versions prior to 3.2.3. Exploitation typically requires an attacker to successfully trick a legitimate user into interacting with a crafted malicious URL or URI containing the malicious payload. Mitigation requires upgrading the Combodo iTop installation to version 3.2.3 or later, where the underlying input sanitization and output encoding flaws within the OQL testing mechanism have been officially resolved by the vendor.",
  "technicalDetails": "The vulnerability resides in the testing OQL query functionality of Combodo iTop prior to version 3.2.3, specifically stemming from inadequate input sanitization, validation, and contextual output encoding of user-supplied parameters. Reflected Cross-Site Scripting (XSS) occurs when an application receives untrusted input within an HTTP request and includes that input immediately within the immediate HTTP response without properly neutralizing executable markup or script tags.\nThe attack vector is network-based, requiring the application to be accessible over the network to potential attackers. In a typical exploitation scenario, an attacker crafts a malicious hyperlink or URL containing a specially engineered payload designed to target the vulnerable testing OQL query feature. The attacker then induces a legitimate, authenticated or unauthenticated user of the iTop application to click the malicious link via social engineering, phishing, or malicious external references.\nUpon receiving the crafted HTTP request, the vulnerable backend component processes the input and subsequently reflects the unescaped payload back to the client within the generated HTML response. When the victim's browser renders the response, the injected JavaScript payload executes within the Document Object Model (DOM) under the security context of the victim's session with the iTop web application.\nBecause the script executes inside the user's browser session, it possesses the ability to access Document properties, manipulate the DOM, intercept sensitive data, read session tokens or cookies if not protected by stringent attributes, and issue asynchronous HTTP requests on behalf of the victim. If the targeted user holds administrative privileges within Combodo iTop, the execution of arbitrary JavaScript can lead to a complete compromise of the application instance, enabling the attacker to perform unauthorized management operations, create administrative accounts, or extract sensitive IT service management data."
}
CVE-2026-30826: Combodo iTop Reflected XSS Vulnerability (HIGH Severity, CVSS: 8.0) - Sceawere