Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in version 3.2.3. | |
| Title | Combodo iTop: Reflected XSS in synchro/synchro_import.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T20:40:05.045Z
Reserved: 2026-03-06T00:04:56.700Z
Link: CVE-2026-30890
No data.
Status : Received
Published: 2026-08-21T21:16:57.103
Modified: 2026-08-21T21:16:57.103
Link: CVE-2026-30890
No data.
OpenCVE Enrichment
Updated: 2026-08-21T21:30:17Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')