Our Malware Labin line with the internal procedures for checking and validating the software used, conducted vulnerability hunting on the open source platform iTopdeveloped by Combodo and widely adopted for IT service management.
The analysis led to the discovery of several critical vulnerabilities in the application's PHP code, as well as misconfigurations in several online instances. These security flaws could have allowed the execution of unauthorised queries, the manipulation of tickets, access to sensitive data, and, in some cases, the complete compromise of misconfigured instances.
All vulnerabilities were responsibly reported to the vendor and, following their correction (or closure as ineligible), we chose to publish the full report.
This work emphasises the importance of the proactive approach to security: every tool introduced into the company can become a potential attack vector if not analysed in depth.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/