CVE-2022-34128
CRITICALGLPI Cartography Plugin <6.0.1 - Remote Code Execution via front/upload.php
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2022-34128. PoCs published by Nuri Çilengir.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote code execution (RCE) vulnerability in GLPI Cartography Plugin v6.0.0. It uploads a malicious PHP file via a POST request to the upload.php endpoint, allowing arbitrary command execution via the cmd parameter.
Description
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Exploits (1)
This exploit demonstrates an unauthenticated remote code execution (RCE) vulnerability in GLPI Cartography Plugin v6.0.0. It uploads a malicious PHP file via a POST request to the upload.php endpoint, allowing arbitrary command execution via the cmd parameter.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H