CVE-2022-34125
MEDIUMGLPI CMDB < 3.0.3 - Unauthenticated Sensitive Information Exposure via File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-34125. PoCs published by Nuri Çilengir.
AI-analyzed exploit summary This exploit demonstrates an authenticated Local File Inclusion (LFI) vulnerability in GLPI Activity plugin versions before 3.1.0. The PoC uses a crafted HTTP GET request to access arbitrary files on the server, such as the Windows hosts file, by traversing directories.
Description
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.
Exploits (1)
This exploit demonstrates an authenticated Local File Inclusion (LFI) vulnerability in GLPI Activity plugin versions before 3.1.0. The PoC uses a crafted HTTP GET request to access arbitrary files on the server, such as the Windows hosts file, by traversing directories.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N