First published: Sun Apr 16 2023(Updated: )
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glpi-project Positions | <6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34128 is a vulnerability in the Cartography (aka positions) plugin for GLPI that allows remote code execution.
CVE-2022-34128 allows an attacker to execute PHP code in the POST data to front/upload.php in the Cartography plugin.
CVE-2022-34128 has a severity rating of 9.8, which is considered critical.
Versions up to and excluding 6.0.1 of the Glpi-project Positions plugin are affected by CVE-2022-34128.
To fix CVE-2022-34128, upgrade to version 6.0.1 or newer of the Cartography (aka positions) plugin for GLPI.