First published: Sun Apr 16 2023(Updated: )
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glpi-project Manageentities | <4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34127 is a vulnerability in the Managentities plugin before version 4.0.2 for GLPI that allows reading local files via directory traversal in the inc/cri.class.php file parameter.
The Managentities plugin version prior to 4.0.2 for GLPI is affected by CVE-2022-34127.
CVE-2022-34127 has a severity rating of 7.5 (high).
To fix CVE-2022-34127, it is recommended to update the Managentities plugin to version 4.0.2 or later.
More information about CVE-2022-34127 can be found in the following references: [GitHub Release](https://github.com/InfotelGLPI/manageentities/releases/tag/4.0.2), [GitHub Security Advisory](https://github.com/InfotelGLPI/manageentities/security/advisories/GHSA-4hpg-m8fv-xv3h), [Pentest Advisory](https://pentest.blog/advisory-glpi-service-management-software-sql-injection-remote-code-execution-and-local-file-inclusion/).