- Description
- Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- itop
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 5.2
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-863
- Hype score
- Not currently trending
[CVE-2025-49145: HIGH] Critical security update for Combodo iTop! Versions below 2.7.13 and 3.2.2 allow admin users to drop the database via webhooks. Update to 2.7.13/3.2.2 to fix this vulnerability.#cve,CVE-2025-49145,#cybersecurity https://t.co/RJzmU3N9L5 https://t.co/olOZDttC
@CveFindCom
10 Nov 2025
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-49145 pertains to a critical security flaw in specific versions of **Combodo iTop**, a widely used web-based IT service management platform. The flaw allows a user with sufficiently elevated privileges—specifically, users capable of creating webhooks (typically
@CveTodo
10 Nov 2025
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-49145 Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators… https://t.co/8hfyc91iPM
@CVEnew
10 Nov 2025
253 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4738ED01-0CAC-4A19-BE9F-B7E89AAD8D23",
"versionEndExcluding": "2.7.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EAF7CD83-4986-43B2-9A2B-3E282671B00F",
"versionEndExcluding": "3.2.2",
"versionStartIncluding": "3.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]