S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-36537 Scanner

CVE-2022-36537 scanner - Information Disclosure vulnerability in ZK Framework

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-36537
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ZK Framework is an open-source web application framework for creating powerful and responsive web applications, leveraging Java-based technology to provide robust and efficient development tools. This framework is widely used by developers across various industries for its robust and reliable features, including client-side validation, customizable themes, and highly interactive components, among others.

Recently, a severe vulnerability - CVE-2022-36537 - was detected in the ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, and 8.6.4.1. This vulnerability is a result of the AuUploader component accepting a crafted POST request, leading to unauthorized access to sensitive information. 

When exploited, the CVE-2022-36537 vulnerability can result in data theft, injection of malicious code, and spread of malware across the network. This could expose sensitive and private data, including customer records, financial information, and account details, leading to significant financial losses and reputational damage to businesses.

In conclusion, the security of digital assets is critical, and it is essential to have pro features and security measures in place to safeguard against potential attacks. The s4e.io platform provides a comprehensive and reliable solution for identifying and addressing security vulnerabilities effectively, providing businesses with the peace of mind they need to focus on their core operations and achieve growth and progress.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is crucial to ensure that all affected ZK Framework versions are updated to the latest available patches. Additionally, it is essential to implement the following precautions to safeguard against potential attacks:

  • Ensure that all security patches and updates are applied promptly to all components, including third-party components, in use.
  • Conduct regular security audits and vulnerability scans to detect potential security threats before they can be exploited.
  • Employ robust security measures such as firewalls, IDS/IPS, and anti-malware solutions to prevent unauthorized access to your network and data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.