Executive brief
A vulnerability exists in the KLiK SocialMediaWebsite platform, which is used for social networking. An attacker can exploit a flaw in how the website handles web requests to perform unauthorized actions or inject malicious content. This could lead to a compromise of user data or unauthorized changes to the website's behavior. Public exploit code is currently available, increasing the risk of an attack.
Technical details
KLiK SocialMediaWebsite 1.0 is vulnerable to an injection flaw within its HTTP GET Request Parameter Handler. The vulnerability is classified under CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component) and CWE-707 (Improper Neutralization). An unauthenticated remote attacker can exploit this by sending specially crafted GET requests. While the specific injection type (e.g., SQLi, XSS) is not explicitly detailed in the advisory, the CVSS vector indicates that user interaction is required (UI:R) and the impact is a partial loss of confidentiality, integrity, and availability. Public exploits are reportedly available.
Affected products
- KLiK SocialMediaWebsite 1.0
Timeline
- 2026-05-25: disclosed
- 2026-05-25: advisory