CVE-2022-31062: Unauthenticated Local File Inclusion
Published Jun 20, 2022
·Updated
Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds b/deploy/index.php file can be deleted if deploy feature is not used.
Affected Software
1 affected component
GLPI-PROJECT Glpi Inventory<1.0.2
Event History
Jun 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-31062?
CVE-2022-31062 has been rated with a high severity due to its potential to allow unauthorized reading of system files.
2
How do I fix CVE-2022-31062?
To remediate CVE-2022-31062, you should upgrade to version 1.0.2 of the Glpi Inventory plugin.
3
What are the workarounds for CVE-2022-31062?
If the deploy feature is not in use, you can mitigate CVE-2022-31062 by deleting the `b/deploy/index.php` file.
4
Which software is affected by CVE-2022-31062?
CVE-2022-31062 affects versions of the Glpi Inventory plugin up to, but not including, version 1.0.2.
5
What type of vulnerability is CVE-2022-31062?
CVE-2022-31062 is a local file inclusion vulnerability that can disclose sensitive system files.