The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-34128.json"