packetstormsecurity.com
http://packetstormsecurity.com/files/171654/GLPI-Glpiinventory-1.0.1-Local-File-Inclusion.html CVE-2022-31062
MEDIUM
Unauthenticated Local File Inclusion
Record summary
CVE-2022-31062 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
glpi-inventory-pluginBrowse glpi-project / glpi-inventory-plugin | CVE List | < 1.0.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBGLPI Glpiinventory v1.0.1 - Unauthenticated Local File InclusionExploitDB exploitby Nuri ÇilengirNot analyzed1 file
References
2github.com
https://github.com/glpi-project/glpi-inventory-plugin/security/advisories/GHSA-q33f-jcjf-p4v9