CVE-2026-9421
Deferred Deferred - Pending Action

Unrestricted File Upload in KLiK SocialMediaWebsite

Vulnerability report for CVE-2026-9421, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-05-25

Last updated on: 2026-05-25

Assigner: VulDB

Description

A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-05-25
Last Modified
2026-05-25
Generated
2026-07-06
AI Q&A
2026-05-26
EPSS Evaluated
2026-07-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
klik socialmediawebsite 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in KLiK SocialMediaWebsite version 1.0, specifically in the function uniqid within the file upload.inc.php of the File Handler component. It allows an attacker to manipulate the function to perform unrestricted file uploads.

Because the vulnerability can be exploited remotely, an attacker can upload files without restriction, potentially bypassing security controls.

Impact Analysis

The unrestricted file upload vulnerability can allow attackers to upload malicious files to the server. This can lead to unauthorized access, data compromise, or the execution of malicious code on the affected system.

Since the attack can be initiated remotely and requires no privileges or user interaction, it poses a significant security risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9421. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart