Vulnerability record · CVE-2022-36537 · published 26 August 2022
CVE-2022-36537: ZK Framework AuUploader information disclosure flaw
Zkoss · Zk Framework
ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allow attackers to access sensitive information through a crafted POST request to the AuUploader component. The record does not describe the underlying weakness beyond a generic CWE-Other label, but the flaw is remotely reachable without authentication and has been exploited in the wild.
Description
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, remotely reachable, listed in CISA KEV with ransomware use, and has an EPSS probability above 0.95.
What it is
ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allow attackers to access sensitive information through a crafted POST request to the AuUploader component. The record does not describe the underlying weakness beyond a generic CWE-Other label, but the flaw is remotely reachable without authentication and has been exploited in the wild.
Impact
An unauthenticated attacker can read sensitive information exposed through the AuUploader endpoint. CISA's KEV entry and third-party reporting tie the flaw to remote code execution in real attacks, so the practical impact can extend beyond data exposure.
Attack surface
The flaw is reached over the network via a crafted POST request to the AuUploader component. The CVSS vector shows no privileges or user interaction required, so any reachable ZK Framework instance is exposed.
Exploitation
CVE-2022-36537 is listed in CISA KEV with a due date of 2023-03-20 and known ransomware campaign use, and EPSS gives it a 30-day probability of 0.954. References include a vendor patch and reporting on active exploitation of an RCE flaw in the same framework.
What to do
- Apply the vendor patch referenced in ZK-5150 for the affected ZK Framework versions.
- If patching is not immediately possible, restrict network access to AuUploader endpoints and block untrusted POST requests at the perimeter.
- Upgrade to a supported ZK Framework release and verify the AuUploader component is not exposed unnecessarily.
- Monitor for and isolate any host showing signs of post-exploitation activity given the KEV ransomware association.
Detection
- Inspect web logs for POST requests to AuUploader paths from unexpected sources or with anomalous payloads.
- Alert on outbound connections or process creation following AuUploader requests on ZK Framework hosts.
- Hunt for known exploitation indicators against the ZK-5150 advisory and CISA KEV guidance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-36537 to the Known Exploited Vulnerabilities catalog on 27 February 2023 as "ZK Framework AuUploader Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 20 March 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://tracker.zkoss.org/browse/ZK-5150 | Issue TrackingPatchVendor Advisory |
| https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-zk-java-framework-rce-flaw/ | Third Party Advisory |
| https://tracker.zkoss.org/browse/ZK-5150 | Issue TrackingPatchVendor Advisory |
| https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-zk-java-framework-rce-flaw/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-36537 | US Government Resource |
Track CVE-2022-36537 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36537), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.