Sceawere

Vulnerability Detail

CVE-2026-30890UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Combodo iTop Reflected XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
3h ago
Vendor
Combodo
Product
iTop
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-08-21T21:16:57.103Z",
  "pubdate": "2026-08-21T21:16:57.103Z",
  "executiveSummary": "A security vulnerability has been identified in Combodo iTop prior to version 3.2.3, specifically manifesting as a Reflected Cross-Site Scripting (XSS) flaw within the synchronization import script. This vulnerability allows remote attackers to inject malicious client-side scripts, typically JavaScript, into HTTP requests directed at the vulnerable application. When an authenticated or unauthenticated user interacts with a specially crafted URL, the malicious payload is reflected back in the HTTP response and executed within the context of the victim's browser session. The primary impact of this vulnerability includes potential session hijacking, credential theft, unauthorized actions performed on behalf of the user, and the manipulation or extraction of sensitive data accessible via the application interface. The risk implication is significant for organizations utilizing affected versions of Combodo iTop, as successful exploitation undermines the integrity and confidentiality of user sessions and web application interactions. Mitigation requires updating the software to version 3.2.3 or later, where the underlying input sanitization and output encoding defects have been officially resolved.",
  "technicalDetails": "The vulnerability resides in the synchro import script component of Combodo iTop prior to version 3.2.3. The root cause of the issue stems from insufficient input validation and improper output encoding of user-supplied data handled by the synchronization import functionality. When parameters passed via HTTP requests are processed and subsequently rendered back to the user without appropriate contextual escaping, the application becomes susceptible to Reflected Cross-Site Scripting (XSS).\nTo exploit this vulnerability, an attacker constructs a malicious URL containing a crafted JavaScript payload embedded within the parameters processed by the synchro import script. The attacker then induces a target user to click the malicious link or visit a third-party resource that automatically triggers the request. Upon receiving the crafted HTTP request, the vulnerable script processes the input and dynamically incorporates the unsanitized payload into the resulting Hypertext Markup Language (HTML) response.\nWhen the victim's browser parses the HTTP response, it interprets the injected payload as legitimate executable script code rather than inert data. The malicious script executes within the security context of the victim's active session, granting the attacker the ability to access Document Object Model (DOM) elements, read session cookies, capture keystrokes, and issue asynchronous HTTP requests to the Combodo iTop instance on behalf of the victim.\nThe attack vector is network-based, requiring the attacker to interact with the web interface of the target Combodo iTop installation. While authentication or specific privilege levels may influence the exact attack surface depending on the accessibility of the synchro import script, the reflected nature of the vulnerability primarily relies on social engineering or malicious linking to target users. Post-exploitation impact encompasses full compromise of the victim browser session, potential escalation of unauthorized interactions within the IT service management tool, and further client-side attacks targeting the organization's infrastructure."
}
CVE-2026-30890: Combodo iTop Reflected XSS Vulnerability (HIGH Severity, CVSS: 8.0) - Sceawere