CVE-2022-36537 is a high-severity information disclosure vulnerability affecting multiple versions of the ZK Framework (9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, and 8.6.4.1). Attackers can exploit this flaw by sending a crafted POST request to the AuUploader component, leading to unauthorized access to sensitive information. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network with no user interaction required, posing a significant risk of data compromise. This CVE is actively exploited, listed in CISA's KEV catalog, and has garnered substantial community and media attention, including reports of its use in ransomware campaigns. While no Metasploit or ExploitDB modules exist, Nuclei templates are available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.6.4.2CPE matchmatch criteria | cpe:2.3:a:zkoss:zk_framework:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.1.3CPE matchmatch criteria | cpe:2.3:a:zkoss:zk_framework:*:*:*:*:*:*:*:* | ||
>= 9.5.0, < 9.5.1.3CPE matchmatch criteria | cpe:2.3:a:zkoss:zk_framework:*:*:*:*:*:*:*:* | ||
>= 9.6.0, < 9.6.2CPE matchmatch criteria | cpe:2.3:a:zkoss:zk_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.