CVE-2024-32870
iTop hub connector Information disclosure
Record summary
CVE-2024-32870 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.
Description
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 5, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List, VulnCheck | < 2.7.11 | affected |
| >= 3.0.0, < 3.0.5 | affected | ||
| >= 3.1.0, < 3.1.2 | affected | ||
| Before 2.7.11 | affected | ||
| 3.0.0 to < 3.0.5 | affected | ||
| 3.1.0 to < 3.1.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMiTop Hub Connector - Information DisclosureCVSS 5.8
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0.
Impact
Unauthenticated attackers can access sensitive server, database, and iTop configuration information.
Remediation
Update iTop to version 2.7.11, 3.0.5, 3.1.2, or 3.2.0 or later.
Source: ProjectDiscovery