CVE-2022-34127

HIGH

Managentities <4.0.2 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-34127. PoCs published by Nuri Çilengir.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated Local File Inclusion (LFI) vulnerability in GLPI Manageentities plugin versions prior to 4.0.2. The PoC uses a crafted HTTP GET request to traverse directories and read arbitrary files, such as the hosts file.

Description

The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.

Exploits (1)

exploitdb WORKING POC
by Nuri Çilengir · textwebappsphp
https://www.exploit-db.com/exploits/51229

This exploit demonstrates an unauthenticated Local File Inclusion (LFI) vulnerability in GLPI Manageentities plugin versions prior to 4.0.2. The PoC uses a crafted HTTP GET request to traverse directories and read arbitrary files, such as the hosts file.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: GLPI Manageentities < 4.0.2
No auth needed
Prerequisites: Network access to the target system · GLPI Manageentities plugin installed and vulnerable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0672
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
glpi-project/manageentities < 4.0.2
Published Apr 16, 2023
Tracked Since Feb 18, 2026