CVE-2022-36537
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 7.5epss 95%
from disclosure to weapon105 days
Published on NVDAug 26
1st PoC+105d
CISA KEV+185d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
Action required by CISAfederal deadline: 2023-03-20
Apply updates per vendor instructions.
Versions
Affected
maven/org.zkoss.zk:zk < 8.6.4.2; maven/org.zkoss.zk:zk >= 9.0.0.0, < 9.0.1.3; maven/org.zkoss.zk:zk >= 9.5.0.0, < 9.5.1.4; maven/org.zkoss.zk:zk >= 9.6.0.0, < 9.6.0.2; maven/org.zkoss.zk:zk >= 9.6.1, < 9.6.2
Fixed in
maven/org.zkoss.zk:zk 8.6.4.2; maven/org.zkoss.zk:zk 9.0.1.3; maven/org.zkoss.zk:zk 9.5.1.4; maven/org.zkoss.zk:zk 9.6.0.2; maven/org.zkoss.zk:zk 9.6.2
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/apublic PoCs found — 6
githubgithub.com/Malwareman007/CVE-2022-36537★ 36githubgithub.com/agnihackers/CVE-2022-36537-EXPLOIT★ 9githubgithub.com/ethan-repo-lab4b6/CVE-2022-36537★ 0vulncheckvulncheck.com/xdb/0508bf2f3fceunverifiedvulncheckvulncheck.com/xdb/5ba33e292bd5unverifiedvulncheckvulncheck.com/xdb/4492cc4717e5unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.