CVE-2026-9421 PUBLISHED

KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload

Assigner: VulDB
Reserved: 24.05.2026 Published: 25.05.2026 Updated: 25.05.2026

A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor n/a
Product KLiK SocialMediaWebsite
Versions
  • Version 1.0 is affected

Credits

  • g111 (VulDB User) reporter
  • VulDB Vulnerability Moderation Team coordinator

References

Problem Types

  • Unrestricted Upload CWE
  • Improper Access Controls CWE