← back
CVE-2025-24021mediumCWE-862

iTop doesn't have mass assignment of fields in the portal form

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Affected products
Combodo · iTop