Junglewise Threat Intelligence

CVE-2026-9422: KLiK SocialMediaWebsite injection in HTTP POST Request Parameter Handler

CVE-2026-9422 · Severity: high · CVSS 7.3 · Published 2026-05-25

Technologies: KLiK SocialMediaWebsite. Vendors: KLiK.

Executive brief

A security vulnerability has been identified in KLiK SocialMediaWebsite 1.0, a social networking platform. The flaw allows remote attackers to inject malicious data into the system via standard web requests. If exploited, this could lead to unauthorized data access, modification of site content, or disruption of services, potentially compromising user privacy and platform integrity.

Technical details

A remote injection vulnerability exists in KLiK SocialMediaWebsite 1.0 within the HTTP POST Request Parameter Handler. The flaw stems from improper neutralization of special elements (CWE-74/CWE-707) during the processing of POST parameters. An unauthenticated attacker can exploit this over the network by sending specially crafted HTTP requests to the server. Successful exploitation allows for various injection-based attacks, potentially leading to unauthorized data disclosure or system manipulation. Public exploit code is reportedly available, increasing the risk of active exploitation.

Affected products

  • KLiK SocialMediaWebsite 1.0

Timeline

  • 2026-05-25: disclosed: Initial publication of the vulnerability details.
  • 2026-05-25: advisory: NVD and VulDB published advisory information.

References

Related threats