Home

Description

A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED Reserved 2026-05-24 | Published 2026-05-25 | Updated 2026-05-25 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR

Problem types

Unrestricted Upload

Improper Access Controls

Timeline

2026-05-24:Advisory disclosed
2026-05-24:VulDB entry created
2026-05-24:VulDB entry last update

Credits

g111 (VulDB User) reporter

VulDB Vulnerability Moderation Team coordinator

References

vuldb.com/vuln/365402 (VDB-365402 | KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload) vdb-entry technical-description

vuldb.com/vuln/365402/cti (VDB-365402 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/submit/813725 (Submit #813725 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 Unrestricted Upload) third-party-advisory

cve.org (CVE-2026-9421)

nvd.nist.gov (CVE-2026-9421)

Download JSON