{"id":"CVE-2025-49145","summary":"iTop admin can drop iTop database using webhooks","details":"Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.","aliases":["GHSA-55q8-mfxr-pq4j"],"modified":"2026-08-12T03:51:19.058007171Z","published":"2025-11-10T21:10:19.742Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49145.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49145.json"},{"type":"ADVISORY","url":"https://github.com/Combodo/iTop/security/advisories/GHSA-55q8-mfxr-pq4j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49145"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/combodo/itop","events":[{"introduced":"0"},{"fixed":"13239c27512253452afd7a88ff77139c85a5f4bb"},{"introduced":"682c821d0ef14224b2182ea5840ae1739600bc22"},{"fixed":"7b44ec23a1b3643dc0d7c5bdf1c108424f3e6d9a"}],"database_specific":{"cpe":"cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.7.13"},{"introduced":"3.0.0"},{"fixed":"3.2.2"}],"source":"CPE_RANGE"}}],"versions":["3.2.1","2.7.12","2.7.11","3.2.0-rc3","3.2.0-rc2","3.2.0-rc1","3.2.0-alpha1","2.7.10","2.7.9","ITSM_Designer_3.1-compatibility","3.1.0-alpha1","2.7.8","2.7.7","2.7.6","2.7.5","2.7.4","2.7.3","1.0.8","2.7.2","2.7.1","2.6.3","2.7.0-beta2","2.7.0-beta","2.7.0-alpha1","2.6.2","2.6.1","N941-2","N941","N2016","N2011","N1963"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49145.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H"}]}