CVE-2022-35914
glpi-project glpi
Published 19 Sept 2022 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 7 Mar 2023, with a remediation deadline of 28 Mar 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
References
- packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.html · Exploit, Third Party Advisory, VDB Entry
- www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed · Patch, Third Party Advisory
- github.com/Orange-Cyberdefense/CVE-repository/ · Third Party Advisory
- github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/POC_2022-35914.sh · Exploit
- github.com/glpi-project/glpi/releases · Release Notes, Third Party Advisory
- glpi-project.org/fr/glpi-10-0-3-disponible/ · Release Notes, Vendor Advisory
- mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914/ · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-35914 · US Government Resource