CVE-2022-35946 is a medium-severity vulnerability affecting GLPI (Gestionnaire Libre de Parc Informatique) versions prior to 10.0.3, stemming from improper input validation in the plugin controller. An authenticated attacker with "General setup" update rights can exploit this to access low-level API functions of the Plugin class, potentially altering database data. The CVSSv3.1 score is 6.5 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N), indicating a network-based attack with low complexity, high privileges required, and high impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.3CPE matchmatch criteria | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.