iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's portal. This is fixed in versions 2.7.12, 3.1.3 and 3.2.1.
CVE ID: CVE-2025-24022
CVSS Base Severity: HIGH
CVSS Base Score: 8.5
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor: Combodo
Product: iTop
EPSS Score: 0.08% (probability of being exploited)
EPSS Percentile: 24.7% (scored less or equal to compared to others)
EPSS Date: 2025-06-12 (when was this score calculated)