CVE-2025-48055 HIGH

CVE-2025-48055: Combodo iTop has stored XSS in user portal's browse brick

Vendor Combodo
Product iTop
Weakness CWE-79 · XSS
Published November 10, 2025
Last update November 10, 2025

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

What the vulnerability does

01Description

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a cross-site scripting attack can occur. This is fixed in versions 3.2.2 and 3.3.0.

Key dates

02Disclosure timeline

November 10, 2025 CVE published
November 10, 2025 Record updated