E23-empl1
CVSS:
7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
False Positive:
f
Variants:
1
Year:
2023
Description
This strike exploits an authentication bypass vulnerability in ZK Java Framework. The vulnerability is due to lack of authentication in ZK AuUploader servlet. A remote unauthenticated attacker can exploit this vulnerability sending a crafted request to the victim server which leads to the disclosure of sensitive files in the context of the webroot.
CVE
References
https://medium.com/numen-cyber-labs/cve-2022-36537-vulnerability-technical-analysis-with-exp-667401766746