CVE-2025-47932
Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is rendered via an AJAX call. Versions 2.7.13 and 3.2.2 sanitize the var responsible for the attack.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47932.json, https://github.com/Combodo/iTop/security/advisories/GHSA-rmxq-fx69-7wg5, https://nvd.nist.gov/vuln/detail/CVE-2025-47932
