NA

CVE-2022-34128

Published: 16/04/2023 Updated: 25/04/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Cartography (aka positions) plugin prior to 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project positions

Exploits

GLPI Cartography versions prior to 600 suffers from a remote shell upload vulnerability ...