← Back to browse · API

CVE-2022-39214

Severity
CRITICAL
CVSS
9.6
EPSS
0.25573
Risk score
47.35
CISA KEV
No
PoC
No
Published
2023-03-14
Modified
2025-02-25
First seen
2026-08-07
Aliases
EUVD-2022-41752
Products
Combodo:iTop 3.0.0, < 3.0.2-1, Combodo:iTop < 2.7.8
Sources
euvd EUVD-2022-41752

Description

Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1.

References