CVE-2022-34128: Malicious File Upload
Published Apr 16, 2023
·Updated
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Affected Software
1 affected component
GLPI-PROJECT Positions Glpi<6.0.1
Event History
Apr 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-34128?
CVE-2022-34128 is a vulnerability in the Cartography (aka positions) plugin for GLPI that allows remote code execution.
2
How does CVE-2022-34128 work?
CVE-2022-34128 allows an attacker to execute PHP code in the POST data to front/upload.php in the Cartography plugin.
3
What is the severity of CVE-2022-34128?
CVE-2022-34128 has a severity rating of 9.8, which is considered critical.
4
Which software versions are affected by CVE-2022-34128?
Versions up to and excluding 6.0.1 of the Glpi-project Positions plugin are affected by CVE-2022-34128.
5
How can I fix CVE-2022-34128?
To fix CVE-2022-34128, upgrade to version 6.0.1 or newer of the Cartography (aka positions) plugin for GLPI.