Junglewise Threat Intelligence

CVE-2022-36537: ZK Framework vulnerable to malicious POST

CVE-2022-36537 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-08-27

Executive brief

The ZK Framework AuUploader component contains a vulnerability that allows remote attackers to retrieve sensitive files from the web context via crafted POST requests. This flaw has been observed in the wild and impacts products utilizing the framework, such as ConnectWise R1Soft Server Backup Manager.

Affected products

  • Potix (ZKoss) ZK Framework 8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1, 9.6.1
  • ConnectWise R1Soft Server Backup Manager

Timeline

  • 2022-08-26: disclosed: NVD Published Date
  • 2023-02-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog