Record summary

CVE-2024-32870 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.

Description

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 5, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheck< 2.7.11affected
>= 3.0.0, < 3.0.5affected
>= 3.1.0, < 3.1.2affected
Before 2.7.11affected
3.0.0 to < 3.0.5affected
3.1.0 to < 3.1.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMiTop Hub Connector - Information DisclosureCVSS 5.8

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by anyone having access to iTop URI. This issue has been patched in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0.

Impact

Unauthenticated attackers can access sensitive server, database, and iTop configuration information.

Remediation

Update iTop to version 2.7.11, 3.0.5, 3.1.2, or 3.2.0 or later.

WeaknessesCWE-200
AuthorsDhiyaneshDk
Template tagscvecve2024itopdisclosureunauthexposurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CPE: cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
Shodan: html:"iTop login"
FOFA: body="iTop login"

Source: ProjectDiscovery

References

1