CVE-2022-35914: Teclib GLPI Remote Code Execution Vulnerability
Published Sep 19, 2022
·Updated
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Other sources
Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
— CISA
Credit
Miguel Redondo
Affected Software
2 affected components
Teclib GLPI
GLPI-PROJECT GLPI<=10.0.2
Remediation
Event History
Sep 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 7, 2023
Known Exploited
via CISA·12:00 AM
May 19, 2024
Exploit Published
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is CVE-2022-35914?
CVE-2022-35914 is a Teclib GLPI Remote Code Execution Vulnerability.
2
What is the severity of CVE-2022-35914?
The severity of CVE-2022-35914 is critical.
3
How does CVE-2022-35914 affect Teclib GLPI?
CVE-2022-35914 affects Teclib GLPI version up to 10.0.2.
4
How can CVE-2022-35914 be exploited?
CVE-2022-35914 allows PHP code injection.
5
Is there a fix available for CVE-2022-35914?
Yes, a fix is available for CVE-2022-35914. It is recommended to update to GLPI version 10.0.3.