claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2022-36537-zk-framework-auuploader.log

CVE-2022-36537 — ZK Framework AuUploader Unspecified Vulnerability

2023-02-27 • CISA Known Exploited Vulnerability


[event] ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

> AFFECTED SOFTWARE

Field Value
Vendor ZK Framework
Product AuUploader
CWE CWE-441
CVE ID CVE-2022-36537
Date Added 2023-02-27
Due Date 2023-03-20
Ransomware Campaign Known — this vulnerability has been leveraged in ransomware campaigns

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2023-03-20

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:11 UTC