HIGH
CVE-2022-36537
CVSS
7.5
KEV
Description
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
Summary dbcve.org
ZK Framework's AuUploader component allows unauthenticated attackers to access sensitive information through specially crafted POST requests. This appears to be an access control or path traversal vulnerability in the file upload component that exposes files that should not be accessible.
Mitigation
Upgrade to a patched version of ZK Framework that addresses this vulnerability, or implement additional access controls on the AuUploader endpoint to restrict unauthorized file access.
EPSS Score
95.4%
Probability of exploitation in next 30 days
99.9th percentile
References
https://tracker.zkoss.org/browse/ZK-5150
Issue Tracking, Patch, Vendor Advisory
https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-zk-java-framework-rce-flaw/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-36537
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.