Description
The web application uses ZK Framework. Due to a vulnerability in the AuUploader component, an unauthenticated attacker can read arbitrary files in the web application context.
Remediation
Upgrade to the latest version of ZK Framework
References
Related Vulnerabilities
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Information Disclosure (5.1.2)
Stack Trace Disclosure (Grails)
WordPress Plugin Health Check & Troubleshooting Arbitrary File Disclosure (1.2.3)
WordPress Plugin WordPress Backup to Dropbox Information Disclosure (4.7.1)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2044)