CVE-2025-48878
BaseFortify
Publication date: 2025-11-10
Last updated on: 2025-11-21
Assigner: GitHub, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| combodo | itop | From 3.0.0 (inc) to 3.2.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Combodo iTop versions prior to 3.2.2 allows a user with a Service desk agent profile to create a ModuleInstallation object when they should not have permission to do so. It is caused by an insecure direct object reference flaw.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized modification of the system by allowing users with limited privileges to create ModuleInstallation objects, potentially leading to integrity issues within the IT service management tool.
What immediate steps should I take to mitigate this vulnerability?
Upgrade Combodo iTop to version 3.2.2 or later, as this version fixes the insecure direct object reference vulnerability.