github.com
https://github.com/InfotelGLPI/positions/releases/tag/6.0.1 CVE-2022-34128
CRITICAL
GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)
Record summary
CVE-2022-34128 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBGLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)ExploitDB exploitby Nuri ÇilengirNot analyzed1 file
References
4github.com
https://github.com/InfotelGLPI/positions/security/advisories/GHSA-947x-g9g9-rcmx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-34128 pentest.blog
https://pentest.blog/advisory-glpi-service-management-software-sql-injection-remote-code-execution-and-local-file-inclusion