8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Description
Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
AI Analysis
A vulnerability in iTop allows an administrator to drop the database using webhooks.
Basic Information
ID
CVE-2025-49145
Source
GitHub_M
Published
Nov 10, 2025 at 21:10
Modified
Nov 10, 2025 at 21:42
Affected Product
Vendor
Combodo
Product
iTop
Version
< 2.7.13
Affected Versions
Combodo iTop < 2.7.13
Combodo iTop >= 3.0.0-alpha, < 3.2.2
Combodo iTop >= 3.0.0-alpha, < 3.2.2
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Combodo
Product
iTop
Version
< 2.7.13, >= 3.0.0-alpha, < 3.2.2