CVE-2022-35914
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Sep 19, 2022
Updated: Jan 7, 2025
CWE ID 74
Summary
CVE-2022-35914 is a vulnerability affecting the GLPI system up to version 10.0.2. The issue lies in the /vendor/htmlawed/htmlawed/htmLawedTest.php file within the htmlawed module. An attacker can inject PHP code due to insufficient input validation, potentially leading to arbitrary code execution and system compromise. This vulnerability poses a serious risk to GLPI installations and requires immediate attention to apply patches or mitigations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GLPI Project
- Glpi-project GLPI
Affected Vendors
- Teclib
- Glpi-project