CVE-2022-35914

glpi-project glpi

Published 19 Sept 2022 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 7 Mar 2023, with a remediation deadline of 28 Mar 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

References