← back
CVE-2022-36537highunder attackransomware

CVE-2022-36537

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 95%
from disclosure to weapon105 days
Published on NVDAug 26
1st PoC+105d
CISA KEV+185d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
Action required by CISAfederal deadline: 2023-03-20

Apply updates per vendor instructions.

Versions

Affected
maven/org.zkoss.zk:zk < 8.6.4.2; maven/org.zkoss.zk:zk >= 9.0.0.0, < 9.0.1.3; maven/org.zkoss.zk:zk >= 9.5.0.0, < 9.5.1.4; maven/org.zkoss.zk:zk >= 9.6.0.0, < 9.6.0.2; maven/org.zkoss.zk:zk >= 9.6.1, < 9.6.2
Fixed in
maven/org.zkoss.zk:zk 8.6.4.2; maven/org.zkoss.zk:zk 9.0.1.3; maven/org.zkoss.zk:zk 9.5.1.4; maven/org.zkoss.zk:zk 9.6.0.2; maven/org.zkoss.zk:zk 9.6.2
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.