CVE-2025-47286

Source
https://cve.org/CVERecord?id=CVE-2025-47286
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47286.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47286
Aliases
  • GHSA-4w93-rw6g-5m9c
Published
2025-11-10T18:38:40Z
Modified
2026-08-12T03:51:13Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Combodo iTop vulnerable to Remote Code Execution in the backup creation functionality
Details

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-74"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47286.json"
}
References

Affected packages

Git / github.com/combodo/itop

Affected ranges

Type
GIT
Repo
https://github.com/combodo/itop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.7.13"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.2.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

1.*
1.0.8
2.*
2.6.1
2.6.2
2.6.3
2.7.0-alpha1
2.7.0-beta
2.7.0-beta2
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
3.*
3.1.0-alpha1
3.2.0-alpha1
3.2.0-rc1
3.2.0-rc2
3.2.0-rc3
3.2.1
ITSM_Designer_3.*
ITSM_Designer_3.1-compatibility
Other
N1963
N2011
N2016
N941
N941-2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47286.json"