{"id":"GHSA-6278-2q4m-cmf3","summary":"ZK Framework vulnerable to malicious POST","details":"ZK Framework version 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.","aliases":["CVE-2022-36537"],"modified":"2025-10-22T19:37:13.966893Z","published":"2022-08-27T00:00:43Z","database_specific":{"github_reviewed_at":"2022-09-16T18:37:18Z","nvd_published_at":"2022-08-26T20:15:00Z","cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36537"},{"type":"WEB","url":"https://github.com/zkoss/zk/commit/92a29aa9b1daf1fd2d9d188cb6545f0441d54e84"},{"type":"PACKAGE","url":"https://github.com/zkoss/zk"},{"type":"WEB","url":"https://tracker.zkoss.org/browse/ZK-5150"},{"type":"WEB","url":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-zk-java-framework-rce-flaw"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-36537"}],"affected":[{"package":{"name":"org.zkoss.zk:zk","ecosystem":"Maven","purl":"pkg:maven/org.zkoss.zk/zk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.6.4.2"}]}],"versions":["2.1.3","2.2.0","2.2.1","2.3.0","2.3.1","2.4.0","2.4.1","2.4.2","2.4.3","3.0.0","3.0.0-RC","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.5.0","3.5.1","3.5.2","3.6.0","3.6.0.1","3.6.1","3.6.2","3.6.2-FL-2009-05-11","3.6.2-FL-20090515","3.6.2.FL.20090518","3.6.2.FL.20090615","3.6.3","5.0.0.RC","5.0.10","5.0.11","5.0.7","5.0.7.1","5.0.8","5.0.9","6.0.0","6.0.1","6.0.2","6.0.2.1","6.5.0","6.5.1","6.5.1.1","6.5.2","6.5.3","6.5.4","7.0.0","7.0.0-Preview","7.0.1","7.0.2","7.0.3","8.0.0","8.0.0-RC","8.0.1","8.0.1.1","8.0.2.2","8.5.0","8.6.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6278-2q4m-cmf3/GHSA-6278-2q4m-cmf3.json"}},{"package":{"name":"org.zkoss.zk:zk","ecosystem":"Maven","purl":"pkg:maven/org.zkoss.zk/zk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0.0"},{"fixed":"9.0.1.3"}]}],"versions":["9.0.0","9.0.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6278-2q4m-cmf3/GHSA-6278-2q4m-cmf3.json"}},{"package":{"name":"org.zkoss.zk:zk","ecosystem":"Maven","purl":"pkg:maven/org.zkoss.zk/zk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.5.0.0"},{"fixed":"9.5.1.4"}]}],"versions":["9.5.0","9.5.0.1","9.5.0.2","9.5.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6278-2q4m-cmf3/GHSA-6278-2q4m-cmf3.json"}},{"package":{"name":"org.zkoss.zk:zk","ecosystem":"Maven","purl":"pkg:maven/org.zkoss.zk/zk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.6.0.0"},{"fixed":"9.6.0.2"}]}],"versions":["9.6.0","9.6.0-jakarta","9.6.0.1","9.6.0.1-jakarta"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6278-2q4m-cmf3/GHSA-6278-2q4m-cmf3.json"}},{"package":{"name":"org.zkoss.zk:zk","ecosystem":"Maven","purl":"pkg:maven/org.zkoss.zk/zk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.6.1"},{"fixed":"9.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-6278-2q4m-cmf3/GHSA-6278-2q4m-cmf3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H"}]}