PT-2022-6454 · Unknown · Zk Framework
Markus Wulftange
·
Published
2022-05-04
·
Updated
2025-11-03
·
CVE-2022-36537
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZK Framework versions 8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1, 9.6.1
Description
The issue is related to the AuUploader component of the ZK Framework, which allows attackers to access sensitive information via a crafted POST request. This can enable a remote attacker to gain unauthorized access to protected information. Approximately 5,600 instances are potentially affected.
Recommendations
For ZK Framework versions 8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1, 9.6.1, consider disabling the AuUploader component until a patch is available to prevent exploitation.
Restrict access to the AuUploader component to minimize the risk of unauthorized access.
Avoid using the AuUploader component in the affected ZK Framework versions until the issue is resolved.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zk Framework