/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
https://senderend.medium.com/pg-practice-box-deep-dive-glpi-c3a1cf1520f8?source=rss------infosec-5
https://senderend.medium.com/pg-practice-box-deep-dive-glpi-c3a1cf1520f8?source=rss------hacking-5
https://glpi-project.org/fr/glpi-10-0-3-disponible/