iTop Mass Assignment Vulnerability in Portal Access Accounts

Vulnerability

A mass assignment vulnerability has been identified in iTop, a web-based IT Service Management tool. This issue affects versions prior to 2.7.12, 3.1.3, and 3.2.1. The vulnerability allows users with portal access to modify object fields that they should not have permission to change.

Impact

Exploitation of this vulnerability allows for unauthorized modification of object fields by users with portal access.

Remediation

Users can upgrade to iTop versions 2.7.12, 3.1.3, or 3.2.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.