vulnerability
Glpi Project Glpi: CVE-2022-35914: Improper Neutralization of Special Elements in Output Used by a Downstream Component
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Sep 19, 2022 | Jul 24, 2025 | Jul 24, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Sep 19, 2022
Added
Jul 24, 2025
Modified
Jul 24, 2025
Description
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Solution
glpi-project-glpi-upgrade-latest
References
- CVE-2022-35914
- https://attackerkb.com/topics/CVE-2022-35914
- URL-http://packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.html
- URL-http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed
- URL-https://github.com/Orange-Cyberdefense/CVE-repository/
- URL-https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/POC_2022-35914.sh
- URL-https://github.com/glpi-project/glpi/releases
- URL-https://glpi-project.org/fr/glpi-10-0-3-disponible/
- URL-https://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914/
- CWE-74
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.