CVE-2025-47286
🟡 Monitoruj
Wykonanie kodu na serwerze w Combodo iTop umożliwia edycja konfiguracji przez administratora.
CVSS
7.2
EPSS
0.5%
Exploit
none
Vendor
combodo
Opis źródłowy (NVD)
Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.2 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-11-10 19:15:57 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje