{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-9420", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-05-24T06:51:54.205Z", "datePublished": "2026-05-25T03:00:12.536Z", "dateUpdated": "2026-05-26T14:21:42.039Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-05-25T03:00:12.536Z" }, "title": "KLiK SocialMediaWebsite HTTP GET Request Parameter injection", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-74", "lang": "en", "description": "Injection" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-707", "lang": "en", "description": "Improper Neutralization" } ] } ], "affected": [ { "vendor": "n/a", "product": "KLiK SocialMediaWebsite", "versions": [ { "version": "1.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:klik_socialmediawebsite:klik_socialmediawebsite:*:*:*:*:*:*:*:*" ], "modules": [ "HTTP GET Request Parameter Handler" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 6.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 6.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-05-24T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-05-24T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-05-24T08:57:02.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "g111 (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB Vulnerability Moderation Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/365401", "name": "VDB-365401 | KLiK SocialMediaWebsite HTTP GET Request Parameter injection", "tags": [ "vdb-entry" ] }, { "url": "https://vuldb.com/vuln/365401/cti", "name": "VDB-365401 | CTI Indicators (IOB, IOC, TTP)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/submit/813723", "name": "Submit #813723 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/813730", "name": "Submit #813730 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection (Duplicate)", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/813731", "name": "Submit #813731 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection (Duplicate)", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/813732", "name": "Submit #813732 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection (Duplicate)", "tags": [ "third-party-advisory" ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-26T14:14:48.344855Z", "id": "CVE-2026-9420", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-26T14:21:42.039Z" } } ] } }