Input validation error in GLPI - CVE-2022-35946
Published: September 14, 2022 / Updated: May 4, 2026
GLPI
glpi-project
Description
The vulnerability allows a remote user to alter database data.
The vulnerability exists due to improper input validation in the plugin controller when handling request input. A remote privileged user can send a specially crafted request to alter database data.
The issue can be used to access the low-level API of the Plugin class.