CVE-2025-48878
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-10

Last updated on: 2025-11-21

Assigner: GitHub, Inc.

Description
Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows a user (e.g. with Service desk agent profile) to create a ModuleInstallation object when they shouldn't be able to do so. Version 3.2.2 fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-10
Last Modified
2025-11-21
Generated
2026-05-07
AI Q&A
2025-11-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
combodo itop From 3.0.0 (inc) to 3.2.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Combodo iTop versions prior to 3.2.2 allows a user with a Service desk agent profile to create a ModuleInstallation object when they should not have permission to do so. It is caused by an insecure direct object reference flaw.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized modification of the system by allowing users with limited privileges to create ModuleInstallation objects, potentially leading to integrity issues within the IT service management tool.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Combodo iTop to version 3.2.2 or later, as this version fixes the insecure direct object reference vulnerability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart