Critical severity9.8CISA KEVNVD Advisory· Published Sep 19, 2022· Updated Jun 17, 2026
CVE-2022-35914
CVE-2022-35914
Description
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: <=10.0.2
- (no CPE)range: <=10.0.2
- GLPI/htmlawed module for GLPIdescription
Patches
Vulnerability mechanics
References
7- www.bioinformatics.org/phplabware/sourceer/sourceer.phpnvdPatchThird Party Advisory
- packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/POC_2022-35914.shnvdExploit
- mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914/nvdExploitThird Party Advisory
- github.com/glpi-project/glpi/releasesnvdRelease NotesThird Party Advisory
- glpi-project.org/fr/glpi-10-0-3-disponible/nvdRelease NotesVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
2- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and MoreThe Hacker News · Jun 8, 2026
- New Gafgyt Variant Targets Multiple Linux Architectures With Modular PropagationCyber Security News · Jun 5, 2026