{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-9421", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-05-24T06:52:00.508Z", "datePublished": "2026-05-25T03:15:09.867Z", "dateUpdated": "2026-05-26T14:40:40.482Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-05-25T03:15:09.867Z" }, "title": "KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-434", "lang": "en", "description": "Unrestricted Upload" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-284", "lang": "en", "description": "Improper Access Controls" } ] } ], "affected": [ { "vendor": "n/a", "product": "KLiK SocialMediaWebsite", "versions": [ { "version": "1.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:klik_socialmediawebsite:klik_socialmediawebsite:*:*:*:*:*:*:*:*" ], "modules": [ "File Handler" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 6.9, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 7.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 7.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-05-24T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-05-24T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-05-24T08:57:24.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "g111 (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB Vulnerability Moderation Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/365402", "name": "VDB-365402 | KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/365402/cti", "name": "VDB-365402 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/submit/813725", "name": "Submit #813725 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 Unrestricted Upload", "tags": [ "third-party-advisory" ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-26T14:40:30.863049Z", "id": "CVE-2026-9421", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-26T14:40:40.482Z" } } ] } }