CVE-2022-36537
high · 7.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2023-02-27Remediation due 2023-03-20
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
7.5
CVSS
95.4%
EPSS (exploit prob.)
100th
EPSS percentile
2022-08-26
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zkoss | zk_framework | < 8.6.4.2 |
| zkoss | zk_framework | >= 9.0.0, < 9.0.1.3 |
| zkoss | zk_framework | >= 9.5.0, < 9.5.1.3 |
| zkoss | zk_framework | >= 9.6.0, < 9.6.2 |
Check a specific version with /api/v1/cve/match.
References
- https://tracker.zkoss.org/browse/ZK-5150
- https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-zk-java-framework-rce-flaw/
- https://tracker.zkoss.org/browse/ZK-5150
- https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-zk-java-framework-rce-flaw/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-36537
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-36537