HIGH

CVE-2022-36537

Zkoss Zk Framework 2022-08-26 CVSS v3.1
CVSS
7.5
KEV

Description

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

Summary dbcve.org

ZK Framework's AuUploader component allows unauthenticated attackers to access sensitive information through specially crafted POST requests. This appears to be an access control or path traversal vulnerability in the file upload component that exposes files that should not be accessible.

Mitigation

Upgrade to a patched version of ZK Framework that addresses this vulnerability, or implement additional access controls on the AuUploader endpoint to restrict unauthorized file access.

Patch Commit

EPSS Score

95.4%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE