KEVIntel
7.5
CVSS
High

CVE-2022-36537

PUBLISHED

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Potix Corporation
Product
ZK Framework
Published
Aug 26, 2022
EPSS

Description

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

cisa malware ransomware nuclei_scanner

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2023-02-27 00:00:00 UTC · Source

Used in malware

Recorded 2023-02-27 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 27, 2023

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Malwareman007/CVE-2022-36537

github · Created 2022-12-09 14:15:52 UTC · 36 stars

POC of CVE-2022-36537

agnihackers/CVE-2022-36537-EXPLOIT

github · Created 2022-12-09 11:29:26 UTC · 9 stars

CVE-2022-36537

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei