Directory Traversal Vulnerability in Managementities Plugin for GLPI
CVE-2022-34127
7.5HIGH
What is CVE-2022-34127?
The Managementities plugin for GLPI, prior to version 4.0.2, contains a directory traversal vulnerability that permits unauthorized access to local files. This flaw is found in the parameter of the inc/cri.class.php file, allowing attackers to exploit this weakness to read sensitive files on the server. Proper mitigation measures and updates to the plugin must be employed to secure affected installations.