Junglewise Threat Intelligence

CVE-2022-35914: Teclib GLPI Remote Code Execution Vulnerability

CVE-2022-35914 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-03-07

Technologies: Teclib GLPI. Vendors: Teclib.

Executive brief

A PHP code injection vulnerability exists in the htmLawedTest.php file within the htmLawed library used by Teclib GLPI. Remote attackers can exploit this to execute arbitrary code on the server via a specially crafted request.

Affected products

  • Teclib GLPI up to and including 10.0.2
  • htmLawed project htmLawed 1.2.9

Timeline

  • 2022-09-19: disclosed: NVD Published Date
  • 2023-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-28: other: CISA KEV due date for remediation

Related threats