Sceawere

Vulnerability Detail

CVE-2026-30864UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Combodo iTop Reflected XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.9
Creation Date
3h ago
Vendor
Combodo
Product
iTop
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.9",
  "pubDate": "2026-08-24T19:16:37.140Z",
  "pubdate": "2026-08-24T19:16:37.140Z",
  "executiveSummary": "Combodo iTop prior to version 3.2.3 contains a Reflected Cross-Site Scripting (XSS) vulnerability within its dashboard revert functionality. This security flaw enables remote attackers to inject malicious client-side scripts, typically JavaScript, into HTTP requests targeting the vulnerable web application. When a victim processes the malicious payload, the injected script executes within the context of their active browser session. The primary impact includes session hijacking, unauthorized actions performed on behalf of the victim, and potential data exfiltration from the IT service management interface. The vulnerability resides specifically in the dashboard management component and requires user interaction, such as clicking a maliciously crafted link, to trigger the reflection and subsequent execution of the payload. Systems running affected iterations of Combodo iTop are at risk until the software is updated to version 3.2.3 or later.",
  "technicalDetails": "The vulnerability is classified as a Reflected Cross-Site Scripting (XSS) flaw affecting the dashboard revert functionality within Combodo iTop prior to version 3.2.3. The root cause stems from insufficient input sanitization and improper output encoding of user-supplied data handled by the vulnerable component during dashboard state reversal operations. When an HTTP request containing malicious input is sent to the application, the server dynamically reflects the unsanitized parameters back into the Hypertext Transfer Protocol response without enforcing context-aware output encoding.\nExploitation occurs when an attacker crafts a malicious URL containing JavaScript payloads targeted at the dashboard revert endpoint and induces a legitimate, authenticated user to access it via network exposure. Upon clicking or navigating to the weaponized link, the victim's browser requests the affected resource, and the web server returns the HTTP response containing the unescaped malicious script. The browser parses the response and executes the script within the Document Object Model (DOM) under the security context of the victim's authenticated session.\nThe attack flow relies on network accessibility to the Combodo iTop web interface and requires the targeted user to be authenticated. Successful execution allows the attacker to leverage the victim's privileges to interact with the IT service management system, manipulate dashboard objects, access sensitive operational data, or perform further client-side attacks. The vulnerability is entirely resolved in Combodo iTop version 3.2.3 through the implementation of robust input validation and strict output encoding mechanisms across the affected dashboard endpoints."
}
CVE-2026-30864: Combodo iTop Reflected XSS Vulnerability (HIGH Severity, CVSS: 8.9) - Sceawere