Server-Side Request Forgery (SSRF) in GLPI - CVE-2022-36112

 

Server-Side Request Forgery (SSRF) in GLPI - CVE-2022-36112

Published: September 14, 2022 / Updated: May 4, 2026


Vulnerability identifier: #VU129527
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2022-36112
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to scan ports or services on the GLPI server or its private network.

The vulnerability exists due to server-side request forgery in RSS feeds and planning when processing RSS feeds or external calendar data. A remote user can supply a crafted feed or calendar source to scan ports or services on the GLPI server or its private network.

Query responses are not exposed to the end user.


Affected software

GLPI

How to mitigate CVE-2022-36112

Install security update from vendor's website.

GLPI - update to 10.0.3

External References

Related Security Bulletins