9.8
CVSS
CVE-2022-34128
RCE
Exploit Found
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Severity: CRITICAL