CVE-2026-9422

HIGH

KLiK SocialMediaWebsite HTTP POST Request Parameter injection

Title source: cna
STIX 2.1

Description

A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used.

References (4)

Core 4
Core References
Vdb Entry vdb-entry
VDB-365403 | KLiK SocialMediaWebsite HTTP POST Request Parameter injection
https://vuldb.com/vuln/365403
Signature, Permissions Required signature permissions-required
VDB-365403 | CTI Indicators (IOB, IOC, TTP)
https://vuldb.com/vuln/365403/cti
Third Party Advisory third-party-advisory
Submit #813734 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection
https://vuldb.com/submit/813734
Third Party Advisory third-party-advisory
Submit #813736 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection (Duplicate)
https://vuldb.com/submit/813736

Scores

CVSS v3 7.3
EPSS 0.0039
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-707 CWE-74
Status published
Products (1)
None/KLiK SocialMediaWebsite 1.0
Published May 25, 2026
Tracked Since May 25, 2026