CVE-2026-31803
8.0Combodo · iTop
Combodo iTop contains a cross-site scripting vulnerability that allows an authenticated user with low privileges to execute arbitrary scripts in the context of the application.
Executive summary
A cross-site scripting vulnerability in Combodo iTop allows authenticated attackers to execute malicious scripts, potentially leading to unauthorized actions or session compromise.
Vulnerability
This is a stored cross-site scripting (XSS) vulnerability categorized as CWE-79. The issue requires the attacker to be authenticated with low privileges and involves a user interaction component, as indicated by the CVSS vector.
Business impact
Successful exploitation allows an attacker to execute malicious scripts within the browser session of other users, including administrators. This can lead to session hijacking, unauthorized data modification, or the performance of administrative actions on behalf of the victim. Given the CVSS score of 8.0, the vulnerability is classified as high severity due to its potential for total impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Upgrade to iTop version 3.2.3 or later to apply the necessary security patches.
Proactive Monitoring: Review application logs for unusual request patterns or suspicious script injections directed at the user interface.
Compensating Controls: Deploy a Web Application Firewall (WAF) with robust cross-site scripting filtering rules to inspect and sanitize incoming traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The high severity of this vulnerability necessitates immediate attention. Organizations should prioritize updating their iTop instances to version 3.2.3 to eliminate the risk of script injection and potential account compromise.