Description
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/Combodo/iTop/security/advisories/GHSA-hggq-48p2-cmhm
Patch x_refsource_misc
https://github.com/Combodo/iTop/commit/35a8b501c9e4e767ec4b36c2586f34d4ab66d229
Patch x_refsource_misc
https://github.com/Combodo/iTop/commit/f10e9c2d64d0304777660a4f70f1e80850ea864b
Scores
CVSS v3
7.4
EPSS
0.0091
EPSS Percentile
55.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-330
Status
published
Products (1)
combodo/itop
2.0.2 - 2.7.8
Published
Mar 14, 2023
Tracked Since
Feb 18, 2026