{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-9422", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-05-24T06:52:22.575Z", "datePublished": "2026-05-25T03:30:10.638Z", "dateUpdated": "2026-05-29T15:26:25.896Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-05-25T03:30:10.638Z" }, "title": "KLiK SocialMediaWebsite HTTP POST Request Parameter injection", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-74", "lang": "en", "description": "Injection" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-707", "lang": "en", "description": "Improper Neutralization" } ] } ], "affected": [ { "vendor": "n/a", "product": "KLiK SocialMediaWebsite", "versions": [ { "version": "1.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:klik_socialmediawebsite:klik_socialmediawebsite:*:*:*:*:*:*:*:*" ], "modules": [ "HTTP POST Request Parameter Handler" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 6.9, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 7.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 7.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "HIGH" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-05-24T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-05-24T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-05-24T08:57:28.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "g111 (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB Vulnerability Moderation Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/365403", "name": "VDB-365403 | KLiK SocialMediaWebsite HTTP POST Request Parameter injection", "tags": [ "vdb-entry" ] }, { "url": "https://vuldb.com/vuln/365403/cti", "name": "VDB-365403 | CTI Indicators (IOB, IOC, TTP)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/submit/813734", "name": "Submit #813734 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/813736", "name": "Submit #813736 | SourceCodester SourceCodester KLiK Social Media Website v1.0.1 CRLF Injection (Duplicate)", "tags": [ "third-party-advisory" ] } ] }, "adp": [ { "references": [ { "url": "https://vuldb.com/submit/813734", "tags": [ "exploit" ] }, { "url": "https://vuldb.com/submit/813736", "tags": [ "exploit" ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-29T15:25:28.920319Z", "id": "CVE-2026-9422", "options": [ { "Exploitation": "poc" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-29T15:26:25.896Z" } } ] } }