PT-2023-13340 · Glpi · Glpi Cartography Plugin

Nuri Çilengir

·

Publicado

2023-04-16

·

Atualizado

2025-02-06

·

CVE-2022-34128

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI Cartography plugin versions prior to 6.0.1
Description The issue allows remote code execution via PHP code in the POST data to "front/upload.php". This enables an attacker to execute arbitrary PHP code on the server.
Recommendations For GLPI Cartography plugin versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "front/upload.php" endpoint to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-34128
GHSA-947X-G9G9-RCMX

Produtos afetados

Glpi Cartography Plugin