PT-2023-13340 · Glpi · Glpi Cartography Plugin

Nuri Çilengir

·

Published

2023-04-16

·

Updated

2025-02-06

·

CVE-2022-34128

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI Cartography plugin versions prior to 6.0.1
Description The issue allows remote code execution via PHP code in the POST data to "front/upload.php". This enables an attacker to execute arbitrary PHP code on the server.
Recommendations For GLPI Cartography plugin versions prior to 6.0.1, update to version 6.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "front/upload.php" endpoint to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-34128
GHSA-947X-G9G9-RCMX

Affected Products

Glpi Cartography Plugin