CVE-2022-36537
26.08.2022, 20:15
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.Enginsight
Vendor | Product | Version |
---|---|---|
zkoss | zk_framework | 𝑥 < 8.6.4.2 |
zkoss | zk_framework | 9.0.0 ≤ 𝑥 < 9.0.1.3 |
zkoss | zk_framework | 9.5.0 ≤ 𝑥 < 9.5.1.3 |
zkoss | zk_framework | 9.6.0 ≤ 𝑥 < 9.6.2 |
𝑥
= Vulnerable software versions
References