Vulnerability Description
iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided layout_class before saving the dashboard.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Combodo | Itop | >= 3.2.0, < 3.2.1 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-24785?
CVE-2025-24785 is a vulnerability with a CVSS score of 4.3 (MEDIUM). iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashe...
How severe is CVE-2025-24785?
CVE-2025-24785 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24785?
Check the references section above for vendor advisories and patch information. Affected products include: Combodo Itop.