CVE-2022-35914
CRITICAL KEV NUCLEIGLPI htmLawed php command injection
Title source: metasploitDescription
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Exploits (11)
metasploit
WORKING POC
EXCELLENT
by cosad3s, bwatters-r7 · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/glpi_htmlawed_php_injection.rb
Nuclei Templates (1)
GLPI <=10.0.2 - Remote Command Execution
CRITICALVERIFIEDby For3stCo1d,allendemoura
Shodan:
http.favicon.hash:"-1474875778" || http.title:"glpi"
FOFA:
icon_hash="-1474875778" || title="glpi"
References (8)
Scores
CVSS v3
9.8
EPSS
0.9439
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2023-03-07
VulnCheck KEV
2022-10-05
InTheWild.io
2022-10-03
ENISA EUVD
EUVD-2022-38785
CWE
CWE-74
Status
published
Products (1)
glpi-project/glpi
< 10.0.2
Published
Sep 19, 2022
KEV Added
Mar 07, 2023
Tracked Since
Feb 18, 2026