GLPI through 10.0.2 is susceptible to remote command execution injection in /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module.
id: CVE-2022-35914
info:
name: GLPI <=10.0.2 - Remote Command Execution
author: For3stCo1d,alle
...