CVE-2022-35914

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 19, 2022
Updated: Jan 7, 2025
CWE ID 74

Summary

CVE-2022-35914 is a vulnerability affecting the GLPI system up to version 10.0.2. The issue lies in the /vendor/htmlawed/htmlawed/htmLawedTest.php file within the htmlawed module. An attacker can inject PHP code due to insufficient input validation, potentially leading to arbitrary code execution and system compromise. This vulnerability poses a serious risk to GLPI installations and requires immediate attention to apply patches or mitigations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • GLPI Project
  • Glpi-project GLPI

Affected Vendors

  • Teclib
  • Glpi-project