« Volver al listado

CVE-2025-27139

Estado: AnalizadaMedia (5.4)—

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-27139",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-27139",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-25T20:07:30.988040Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "Combodo",
          "product": "iTop",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.7.12"
            },
            {
              "status": "affected",
              "version": ">= 3.0.0-alpha, < 3.1.2"
            },
            {
              "status": "affected",
              "version": ">= 3.2.0-alpha1, < 3.2.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-02-25T20:15:37.693",
  "references": [
    {
      "url": "https://github.com/Combodo/iTop/security/advisories/GHSA-c6mg-9537-c8cf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the preferences page is opened. Versions 2.7.12, 3.1.2, and 3.2.0 fix the issue."
    },
    {
      "lang": "es",
      "value": "Combodo iTop es una herramienta de gestión de servicios de TI basada en la web. Las versiones anteriores a 2.7.12, 3.1.2 y 3.2.0 son vulnerables a ataques de cross site scripting cuando se abre la página de preferencias. Las versiones 2.7.12, 3.1.2 y 3.2.0 solucionan el problema."
    }
  ],
  "lastModified": "2026-06-17T09:03:05.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC277226-1ABB-4593-B14C-4910541DA298",
              "versionEndExcluding": "2.7.12"
            },
            {
              "criteria": "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91456038-80B6-479B-BBDF-9376B9D2F100",
              "versionEndExcluding": "3.1.2",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:combodo:itop:3.2.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C62AC350-F938-43A2-B066-3CEF23B03C0C"
            },
            {
              "criteria": "cpe:2.3:a:combodo:itop:3.2.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2E2A04B-A0E6-4906-BD91-91DAC92CC067"
            },
            {
              "criteria": "cpe:2.3:a:combodo:itop:3.2.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24D309D2-E86C-4222-B258-C09BEEF42CD2"
            },
            {
              "criteria": "cpe:2.3:a:combodo:itop:3.2.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6613DB9B-E3F9-44CC-B46A-77739060B641"
            },
            {
              "criteria": "cpe:2.3:a:combodo:itop:3.2.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C86A4B5-375A-4761-A853-AB0EED54A540"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}