{"id":"CVE-2022-36537","vendor_project":"ZK Framework","product":"AuUploader","vulnerability_name":"ZK Framework AuUploader Unspecified Vulnerability","date_added":"2023-02-27","due_date":"2023-03-20","known_ransomware_use":"Known","short_description":"ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.","required_action":"Apply updates per vendor instructions.","cwes":"CWE-441","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","nvd_published":"2022-08-26","nvd_status":"Analyzed","epss":0.95397,"epss_percentile":0.99867,"cvss_score":7.5,"days_published_to_kev":185,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2022-36537","by":"CyberMax"}