CVE-2022-35914
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
19/09/2022
Last modified:
03/11/2025
Description
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | 10.0.2 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.html
- http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?Sfs=htmLawedTest.php&Sl=./internal_utilities/htmLawed
- https://github.com/Orange-Cyberdefense/CVE-repository/
- https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/POC_2022-35914.sh
- https://github.com/glpi-project/glpi/releases
- https://glpi-project.org/fr/glpi-10-0-3-disponible/
- https://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914/
- http://packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.html
- http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?Sfs=htmLawedTest.php&Sl=./internal_utilities/htmLawed
- https://github.com/glpi-project/glpi/releases
- https://glpi-project.org/fr/glpi-10-0-3-disponible/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-35914



