CVE-2025-49145

8.7

Combodo · iTop

A vulnerability in Combodo iTop allows authenticated administrators to perform unauthorized database deletion via improperly validated webhook callbacks.

Executive summary

A critical authorization flaw in Combodo iTop allows privileged users to delete the application database, posing a severe risk to service availability and data integrity.

Vulnerability

The application fails to properly verify callback signatures for webhooks, allowing an authenticated user with administrative privileges to execute unauthorized database deletion commands.

Business impact

The ability for an attacker to drop the application database represents a total loss of service availability and potential permanent data destruction. Given the CVSS score of 8.7, this vulnerability is classified as High severity because it provides a direct path for malicious actors to sabotage critical IT service management infrastructure, leading to significant operational disruption and recovery costs.

Remediation

Immediate Action: Update Combodo iTop to version 2.7.13 or 3.2.2 immediately to implement the required callback signature verification.

Proactive Monitoring: Review administrative access logs and audit the creation of new webhooks to identify suspicious configuration activity or unauthorized attempts to modify database settings.

Compensating Controls: Restrict administrative access to the iTop management interface to trusted internal networks only, and ensure that database backups are stored in an immutable, off-site location to mitigate the impact of potential data loss.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability in Combodo iTop presents a significant risk to the availability of IT management services. Administrators must prioritize the application of the vendor-supplied patches to versions 2.7.13 or 3.2.2 to close the authorization gap. Failure to remediate could allow an attacker with administrative access to cause irreversible damage to the underlying database, resulting in prolonged system downtime.

More Combodo CVEs

Sources