漏洞描述
GLPI through 10.0.2 is susceptible to remote command execution injection in /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
mayfly277.github.iohttps://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914↗www.bioinformatics.orghttp://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-35914↗github.comhttps://github.com/glpi-project/glpi/releases↗senderend.medium.comhttps://senderend.medium.com/pg-practice-box-deep-dive-glpi-c3a1cf1520f8↗github.comhttps://github.com/allendemoura/CVE-2022-35914↗