github.com
https://github.com/InfotelGLPI/manageentities/releases/tag/4.0.2 CVE-2022-34127
HIGH
GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin
Record summary
CVE-2022-34127 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBGLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities pluginExploitDB exploitby Nuri ÇilengirNot analyzed1 file
References
4github.com
https://github.com/InfotelGLPI/manageentities/security/advisories/GHSA-4hpg-m8fv-xv3h nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-34127 pentest.blog
https://pentest.blog/advisory-glpi-service-management-software-sql-injection-remote-code-execution-and-local-file-inclusion