Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5371 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue. |
Fri, 28 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Combodo
Combodo itop |
|
| CPEs | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* cpe:2.3:a:combodo:itop:3.2.0:alpha1:*:*:*:*:*:* cpe:2.3:a:combodo:itop:3.2.0:beta1:*:*:*:*:*:* cpe:2.3:a:combodo:itop:3.2.0:rc1:*:*:*:*:*:* cpe:2.3:a:combodo:itop:3.2.0:rc2:*:*:*:*:*:* cpe:2.3:a:combodo:itop:3.2.0:rc3:*:*:*:*:*:* |
|
| Vendors & Products |
Combodo
Combodo itop |
Tue, 25 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue. | |
| Title | Combodo iTop vulnerable to stored self Cross-site Scripting in preferences | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T20:07:39.635Z
Reserved: 2025-02-19T16:30:47.776Z
Link: CVE-2025-27139
Updated: 2025-02-25T20:07:35.293Z
Status : Analyzed
Published: 2025-02-25T20:15:37.693
Modified: 2025-02-28T13:35:22.340
Link: CVE-2025-27139
No data.
OpenCVE Enrichment
No data.
EUVD