References https://nvd.nist.gov/vuln/detail/CVE-2022-35914 https://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914/ https://github.com/glpi-project/glpi/security/advisories/GHSA-c5gx-789q-5pcr https://github.com/cosad3s/CVE-2022-35914-poc https://www.sentinelone.com/vulnerability-database/cve-2022-35914/ https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/GLPI-htmLawedTest.php-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2022-35914.md https://avd.aliyun.com/detail?id=AVD-2022-35914 https://glpi-project.org/fr/glpi-10-0-3-disponible/ https://www.exploit-db.com/exploits/52023 https://cve.imfht.com/detail/CVE-2022-35914
Related VulnerabilitiesPoCCVE-2026-53629: GLPI - Blind SQL Injection in History Log Filter (LogBleed)PoCGLPI /ajax/telemetry.php 权限绕过漏洞(CVE-2024-50339)GLPI /index.php/ajax/ SQL 注入漏洞(CVE-2025-24799)PoCCVE-2019-10232: Teclib GLPI <= 9.3.3 - Unauthenticated SQL InjectionPoCCVE-2020-11034: GLPI <9.4.6 - Open RedirectPoCCVE-2021-39211: GLPI 9.2/<9.5.6 - Information DisclosurePoCCVE-2021-43778: GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.PoCCVE-2022-35914: GLPI <=10.0.2 - Remote Command ExecutionPoCCVE-2024-29889: GLPI 10.0.10-10.0.14 - SQL InjectionPoCCVE-2025-24799: GLPI < 10.0.17 - Pre-Auth SQL InjectionPoCglpi-default-login: GLPI Default LoginPoCglpi-directory-listing: GLPI - Directory Listing and Session Exposure