CVE-2022-36537
ZK Framework AuUploader: Unspecified
As of , CVE-2022-36537 in ZK Framework AuUploader is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 27 February 2023
- US federal deadline
- 20 March 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Known
- EPSS score
- 0.95Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.17 on 27 February 2023EPSS on the day CISA listed it.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: tracker.zkoss.orgLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.
CISA's description
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
The CVE record's description, from mitre
- CVE published
- 26 August 2022
- Assigned by
- mitre
- CVSS
- 7.5 High (CVSS 3.1, from CISA-ADP)
- CWE-441
- Unintended Proxy or Intermediary ('Confused Deputy')
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org