PT-2022-6454 · Unknown · Zk Framework

Markus Wulftange

·

Published

2022-05-04

·

Updated

2025-11-03

·

CVE-2022-36537

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZK Framework versions 8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1, 9.6.1
Description The issue is related to the AuUploader component of the ZK Framework, which allows attackers to access sensitive information via a crafted POST request. This can enable a remote attacker to gain unauthorized access to protected information. Approximately 5,600 instances are potentially affected.
Recommendations For ZK Framework versions 8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1, 9.6.1, consider disabling the AuUploader component until a patch is available to prevent exploitation. Restrict access to the AuUploader component to minimize the risk of unauthorized access. Avoid using the AuUploader component in the affected ZK Framework versions until the issue is resolved.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-01444
CVE-2022-36537
GHSA-6278-2Q4M-CMF3

Affected Products

Zk Framework