CVE-2025-47286

HIGH

Combodo iTop < 2.7.13 - Authenticated Remote Code Execution via Configuration Parameter

Title source: llm
STIX 2.1

Description

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0041
EPSS Percentile 32.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (1)
combodo/itop < 2.7.13
Published Nov 10, 2025
Tracked Since Feb 18, 2026