CVE-2022-35914
CRITICALCVSS 9.8/10Actively ExploitedEPSS 99.52%
Last modified
CVE-2022-35914 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.52% chance of exploitation in the next 30 days.
Description
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Glpi-Project | Glpi | <= 10.0.2 |
References
- https://packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/Orange-Cyberdefense/CVE-repository/Third Party Advisory
- https://github.com/glpi-project/glpi/releasesRelease Notes, Third Party Advisory
- https://glpi-project.org/fr/glpi-10-0-3-disponible/Release Notes, Vendor Advisory
- https://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914/Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/glpi-project/glpi/releasesRelease Notes, Third Party Advisory
- https://glpi-project.org/fr/glpi-10-0-3-disponible/Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-35914US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-35914?
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
How severe is CVE-2022-35914?
CVE-2022-35914 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 99.52% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2022-35914?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-35909In Jellyfin before 10.8, the /users endpoint has incorrect a…8.8
- CVE-2022-3591Use After Free in GitHub repository vim/vim prior to 9.0.078…7.8
- CVE-2022-35910In Jellyfin before 10.8, stored XSS allows theft of an admin…5.4
- CVE-2022-35911On Patlite NH-FB series devices through 1.46, remote attacke…7.5
- CVE-2022-35912In grails-databinding in Grails before 3.3.15, 4.x before 4.…9.8
- CVE-2022-35913Samourai Wallet Stonewallx2 0.99.98e allows a denial of serv…4.3
- CVE-2022-35915OpenZeppelin Contracts is a library for secure smart contrac…5.3
- CVE-2022-35916OpenZeppelin Contracts is a library for secure smart contrac…5.3
- CVE-2022-35917Solana Pay is a protocol and set of reference implementation…5.3
- CVE-2022-35918Streamlit is a data oriented application development framewo…6.5
- CVE-2022-35919MinIO is a High Performance Object Storage released under GN…2.7
- CVE-2022-3592A symlink following vulnerability was found in Samba, where …6.5
Are you affected by CVE-2022-35914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
