References https://github.com/glpi-project/glpi/security/advisories/GHSA-c5gx-789q-5pcr https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/glpi_htmlawed_php_injection.rb https://sploitus.com/exploit?id=MSF:EXPLOIT-LINUX-HTTP-GLPI_HTMLAWED_PHP_INJECTION- https://stack.chaitin.com/vuldb/detail/71e4d8de-28ec-41e2-a373-e2d773509978 https://www.cert.ssi.gouv.fr/alerte/CERTFR-2022-ALE-010/ https://packetstormsecurity.com/files/169501/GLPI-10.0.2-Command-Injection.html https://vulnerability.circl.lu/vuln/CVE-2022-35914 https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:CTS:GLPI-HTMLLAWEDTEST-RCE.html https://github.com/Orange-Cyberdefense/CVE-repository/ https://github.com/cosad3s/CVE-2022-35914-poc
Related VulnerabilitiesPoCCVE-2026-53629: GLPI - Blind SQL Injection in History Log Filter (LogBleed)PoCclaude-settings-exposure: Claude Code Project Settings Exposure关于用友GRP-U8Cloud产品getBudgetReleaseProjectList及U8AppProxy及fbpm-modeler存在命令执行漏洞的安全通告FOGProject /fog/management/export.php 信息泄露漏洞(CVE-2025-58443)PoCCVE-2026-47717: FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data DisclosureTRUfusion Enterprise /trufusionPortal/getProjectList 权限绕过漏洞(CVE-2025-27223)FUXA /api/project 信息泄露漏洞(CVE-2026-47717)孚盟云 CRM /PageStructure/Normal/TfrmProject.aspx 文件读取漏洞PoCGLPI /ajax/telemetry.php 权限绕过漏洞(CVE-2024-50339)PoCopenproject-default-login: OpenProject - Default Admin CredentialsFUXA /api/project 权限绕过漏洞(CVE-2025-69971)OpenProject存在默认口令PoCCVE-2024-13114: WP Projects Portfolio <= 3.0 - Cross-Site Scripting