CVE-2022-35914 | GLPI up to 10.0.2 htmlawed Module htmLawedTest.php code injection (EDB-52023)
A vulnerability was found in GLPI up to 10.0.2. It has been declared as critical. This vulnerability affects unknown code of the file /vendor/htmlawed/htmlawed/htmLawedTest.php of the component htmlawed Module. The manipulation leads to code injection.
This vulnerability was named CVE-2022-35914. The attack can only be initiated within the local network. Furthermore, there is an exploit available.