Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
References
| Link | Resource |
|---|---|
| https://github.com/Combodo/iTop/security/advisories/GHSA-55q8-mfxr-pq4j | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2025, 13:37
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Combodo/iTop/security/advisories/GHSA-55q8-mfxr-pq4j - Vendor Advisory | |
| First Time |
Combodo itop
Combodo |
|
| CPE | cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:* |
10 Nov 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-10 22:15
Updated : 2025-11-21 13:37
NVD link : CVE-2025-49145
Mitre link : CVE-2025-49145
CVE.ORG link : CVE-2025-49145
JSON object : View
Products Affected
combodo
- itop
CWE
CWE-863
Incorrect Authorization
