S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-35914 Scanner

CVE-2022-35914 scanner - Code Injection vulnerability in GLPI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-35914
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

GLPI, a web-based IT service management software, is widely used to manage IT infrastructure, help desks, and assets across many businesses and organizations. With a user-friendly interface and a comprehensive list of features, GLPI simplifies the daunting task of maintaining and tracking IT systems. Its modules help streamline IT service requests, improve support ticket management, and ensure that computer hardware and software systems are up-to-date. GLPI is an open-source software that is freely available to users, and has been praised for its flexibility and customization options.

However, CVE-2022-35914 is a vulnerability that was discovered in GLPI Version 10.0.2, specifically in the htmLawedTest.php file within the htmlawed module. This vulnerability can be exploited to inject PHP code into the system, which can then execute arbitrary code. The severity of this vulnerability is considerable, as it could lead to loss of data, system crashes, and unauthorized access to sensitive information. This vulnerability can be easily exploited by attackers who have access to the system, which is a significant concern for businesses and organizations.

If an attacker successfully exploits CVE-2022-35914, they can perform various malicious actions, such as installing malware, stealing data, and compromising the integrity of the system. It can also allow attackers to gain access to privileged accounts and critical systems, which can lead to severe damage to the organization. The consequences of this vulnerability could be devastating and can significantly impact businesses and organizations.

In conclusion, CVE-2022-35914 is a vulnerability that can seriously impact the security of GLPI installations. Businesses and organizations need to take appropriate measures to mitigate the risks associated with such vulnerabilities. By using security monitoring tools, such as the pro features of the s4e.io platform, businesses and organizations can quickly and easily identify vulnerabilities in their digital assets, enabling them to address security issues promptly and effectively.

 

REFERENCES

Solution Advice

To protect against CVE-2022-35914, businesses and organizations can consider the following precautions:

  • Regularly update the GLPI software to the latest version.
  • Restrict access to the system and modules to authorized personnel only.
  • Implement strong password policies and two-factor authentication for all users.
  • Use firewalls, intrusion detection systems, and antivirus software to protect the system against attacks.
  • Use secure coding practices to prevent the exploitation of vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-35914 scanner - Code Injection vulnerability in GLPI S4E