← Back
Web Application
CVE-2026-27462 high CVSS 7.5

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...

Summary

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.

AI summary openai / gpt-4o

Combodo iTopのバージョン3.2.3より前では、パスワードリセット時に有効なユーザー名と無効なユーザー名に対して異なる応答を返すことで、ユーザーの列挙が可能となる脆弱性が存在します。この問題はバージョン3.2.3で修正されています。
❓ What is the problem
Combodo iTopにおけるパスワードリセットのメカニズムが、ユーザー名の有効性に基づいて異なる応答を返す脆弱性。
📍 Affected scope
iTopのバージョン3.2.3より前
🔥 Severity
高い重大度で、ユーザー列挙攻撃のリスクがある。
🔧 How to fix
iTopをバージョン3.2.3にアップデートすることで脆弱性が修正される。
🛡️ Workaround
情報なし
🔍 Detection
iTopのバージョンをチェックし、3.2.3未満であれば影響を受ける可能性がある。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →