iTop Picture ID Manipulation Vulnerability Allowing Unauthorized Access to Contact Images

Vulnerability

A vulnerability in iTop, a web-based IT Service Management tool, prior to version 3.2.1, allows portal users to view any contact's picture by altering the picture ID in the URL. This issue has been addressed in version 3.2.1.

Impact

Exploitation of this vulnerability allows a portal user to access and view pictures of other contacts without authorization.

Remediation

Users can upgrade to iTop version 3.2.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.