Home

Description

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.

PUBLISHED Reserved 2025-01-16 | Published 2025-05-14 | Updated 2026-01-20 | Assigner GitHub_M




HIGH: 8.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

< 2.7.12
affected

>= 3.0.0, < 3.1.3
affected

>= 3.2.0, < 3.2.1
affected

References

github.com/...o/iTop/security/advisories/GHSA-rhv2-wfrr-4j2j

github.com/...ommit/082d865efaf8a349b60fe3875e9c726c24f8a8bd

github.com/...ommit/37fc1a572380f2faa67fddea5b1a3a4ba72ed54e

github.com/...ommit/5780f26817c2303c5bdd0ad16e21d4d959780b0b

cve.org (CVE-2025-24022)

nvd.nist.gov (CVE-2025-24022)

Download JSON