← back
CVE-2024-32870mediumobserved exploitationCWE-200

iTop hub connector Information disclosure

50Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 5.8epss 0.8%
from disclosure to weapon
Published on NVDNov 4
VulnCheck+216d
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
yesVulnCheck
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Affected products
Combodo · iTop