iTop Server Code Execution Vulnerability

Vulnerability

A vulnerability allowing server-side code execution has been identified in iTop, a web-based IT Service Management tool. This issue affects versions prior to 2.7.12, 3.1.3, and 3.2.1. The vulnerability arises from a code injection in the portal's frontend, which could be exploited to execute arbitrary code on the iTop server.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where iTop is hosted.

Remediation

Users can upgrade to iTop versions 2.7.12, 3.1.3, or 3.2.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
10.0
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.